omero-web has 5 CVEs on record between 2021 and 2025. The median CVSS is 6.1 (medium), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- omero-web 5
5
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2021-41132Critical· 9.8Inconsistent input sanitisation leads to XSS vectors54CVE-2021-21376Medium· 6.4OMERO.web exposes some unnecessary session information in the page35CVE-2024-35180Medium· 6.1OMERO.web must check that the JSONP callback is a valid function34CVE-2025-54791Medium· 5.3OMERO.web displays unecessary user information when requesting password reset29CVE-2021-21377Medium· 4.8OMERO webclient does not validate URL redirects on login or switching group.27
omero-web vulnerabilities
CVEs affecting omero-web, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2025-54791Medium· 5.3OMERO.web displays unecessary user information when requesting password reset
OMERO.web displays unecessary user information when requesting password reset
▾ Sunlitomero-web · omero-webEPSS 0.26%via OSV
CVE-2024-35180Medium· 6.1OMERO.web must check that the JSONP callback is a valid function
OMERO.web must check that the JSONP callback is a valid function
▾ Sunlitomero-web · omero-webEPSS 0.29%via OSV
CVE-2021-41132Critical· 9.8Inconsistent input sanitisation leads to XSS vectors
Inconsistent input sanitisation leads to XSS vectors
▾ Midnightomero-web · omero-webEPSS 1.0%via OSV
CVE-2021-21376Medium· 6.4OMERO.web exposes some unnecessary session information in the page
OMERO.web exposes some unnecessary session information in the page
▾ Sunlitomero-web · omero-webEPSS 1.5%via OSV
CVE-2021-21377Medium· 4.8OMERO webclient does not validate URL redirects on login or switching group.
OMERO webclient does not validate URL redirects on login or switching group.
▾ Sunlitomero-web · omero-webEPSS 0.83%via OSV