omero-web vulnerabilities
CVEs whose affected-version data names the omero-web package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2025-54791Medium· 5.3OMERO.web displays unecessary user information when requesting password reset
OMERO.web displays unecessary user information when requesting password reset
▾ Sunlitomero-web · omero-webEPSS 0.26%via OSV
CVE-2024-35180Medium· 6.1OMERO.web must check that the JSONP callback is a valid function
OMERO.web must check that the JSONP callback is a valid function
▾ Sunlitomero-web · omero-webEPSS 0.29%via OSV
CVE-2021-41132Critical· 9.8Inconsistent input sanitisation leads to XSS vectors
Inconsistent input sanitisation leads to XSS vectors
▾ Midnightomero-web · omero-webEPSS 1.0%via OSV
CVE-2021-21376Medium· 6.4OMERO.web exposes some unnecessary session information in the page
OMERO.web exposes some unnecessary session information in the page
▾ Sunlitomero-web · omero-webEPSS 1.5%via OSV
CVE-2021-21377Medium· 4.8OMERO webclient does not validate URL redirects on login or switching group.
OMERO webclient does not validate URL redirects on login or switching group.
▾ Sunlitomero-web · omero-webEPSS 0.83%via OSV