CVE-2021-41132Critical· 9.8▾ MidnightInconsistent input sanitisation leads to XSS vectors
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
1.0% → 1.0%
A variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of jQuery.html(), there are a whole host of XSS possibilities with specially crafted input to a variety of fields.
OMERO.web before 5.11.0 and OMERO.figure before 4.4.1.
Users should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher.
omero-web < 5.11.0omero-figure < 4.4.1Upgrade to a patched release:
omero-web 5.11.0omero-figure 4.4.1Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21376Medium· 6.4OMERO.web exposes some unnecessary session information in the page
CVE-2024-35180Medium· 6.1OMERO.web must check that the JSONP callback is a valid function
CVE-2025-54791Medium· 5.3OMERO.web displays unecessary user information when requesting password reset
CVE-2021-21377Medium· 4.8OMERO webclient does not validate URL redirects on login or switching group.