VYPR

Omero Web

by Openmicroscopy

Source repositories

CVEs (3)

  • CVE-2021-41132CriOct 14, 2021
    risk 0.57cvss 9.8epss 0.01

    OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitization through HTML escaping. Due to the lack of sanitization and use of ``jQuery.html()``, there are a whole host of cross-site…

  • CVE-2024-35180MedMay 21, 2024
    risk 0.33cvss 6.1epss 0.00

    OMERO.web provides a web based client and plugin infrastructure. There is currently no escaping or validation of the `callback` parameter that can be passed to various OMERO.web endpoints that have JSONP enabled. This vulnerability has been patched in version 5.26.0.

  • CVE-2025-54791MedAug 13, 2025
    risk 0.27cvss 5.3epss 0.00

    OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when resetting a user's password using the Forgot Password option in OMERO.web, the error message displayed on the Web page can disclose information about the user.…