omero-web
Django-based OMERO.web client
Activity
- Latest release
- 5d ago
- Total releases
- 58
- Cadence
- ~44 days
- Last 12 months
- 8
Reach
- Stars
- 24
Details
- License
- GPL-2.0
- First release
- Aug 27, 2019
| Version | Released | |
|---|---|---|
5.33.1
patch
| ||
5.33.0
minor
| ||
5.32.0
minor
| ||
5.31.1
patch
| ||
5.31.0
minor
| ||
5.30.1
patch
| ||
5.30.0
minor
| ||
5.29.3
patch
| ||
5.29.2
patch
1 CVE
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.29.1
patch
2 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.29.0
minor
2 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.28.0
minor
2 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.27.2
patch
2 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.27.1
patch
2 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.27.0
minor
2 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.26.0
minor
2 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.25.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.24.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.23.1.dev0
pre
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.23.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.22.1
patch
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.22.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.21.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.20.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.19.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.18.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.17.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.16.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.15.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.14.1
patch
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.14.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.14.0rc1
pre
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.13.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.12.1
patch
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.12.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.11.0
minor
3 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev | ||
5.11.0rc1
pre
4 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
5.10.0
minor
4 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
5.9.2
patch
4 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
5.9.1
patch
4 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
5.9.0
minor
4 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
5.8.1
patch
6 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21377
PYSEC-2021-32
GHSA-g4rf-pc26-6hmr
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21376
PYSEC-2021-31
GHSA-gfp2-w5jm-955q
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.8.0
minor
6 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21377
PYSEC-2021-32
GHSA-g4rf-pc26-6hmr
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21376
PYSEC-2021-31
GHSA-gfp2-w5jm-955q
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.7.1
patch
6 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21377
PYSEC-2021-32
GHSA-g4rf-pc26-6hmr
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21376
PYSEC-2021-31
GHSA-gfp2-w5jm-955q
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.7.0
minor
6 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21377
PYSEC-2021-32
GHSA-g4rf-pc26-6hmr
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21376
PYSEC-2021-31
GHSA-gfp2-w5jm-955q
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.6.3
patch
6 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21377
PYSEC-2021-32
GHSA-g4rf-pc26-6hmr
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21376
PYSEC-2021-31
GHSA-gfp2-w5jm-955q
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.6.2
patch
7 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2020-7932
GHSA-vwxv-frj6-fhc9
PYSEC-2020-244
May 24, 2022
OMERO-web Sensitive Data Exposure
Medium
Network
Low
Low
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed. Affected versions
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
Fixed in
5.6.3
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21377
PYSEC-2021-32
GHSA-g4rf-pc26-6hmr
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21376
PYSEC-2021-31
GHSA-gfp2-w5jm-955q
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.6.1
patch
7 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2020-7932
GHSA-vwxv-frj6-fhc9
PYSEC-2020-244
May 24, 2022
OMERO-web Sensitive Data Exposure
Medium
Network
Low
Low
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed. Affected versions
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
Fixed in
5.6.3
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21377
PYSEC-2021-32
GHSA-g4rf-pc26-6hmr
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21376
PYSEC-2021-31
GHSA-gfp2-w5jm-955q
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.6.0
initial
7 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2020-7932
GHSA-vwxv-frj6-fhc9
PYSEC-2020-244
May 24, 2022
OMERO-web Sensitive Data Exposure
Medium
Network
Low
Low
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed. Affected versions
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
Fixed in
5.6.3
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21377
PYSEC-2021-32
GHSA-g4rf-pc26-6hmr
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21376
PYSEC-2021-31
GHSA-gfp2-w5jm-955q
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
5.6.dev7
pre
7 CVEs
CVE-2025-54791
PYSEC-2026-1717
GHSA-gpmg-4x4g-mr5r
Jul 07, 2026
OMERO.web displays unecessary user information when requesting password reset
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
BackgroundIf an error occurred when resetting a user's password using the ImpactOMERO.web before 5.29.1 PatchesUser should upgrade to 5.29.2 or higher WorkaroundsDisable the Thanks to Christopher Youd who reported the issue. Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 37 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-35180
PYSEC-2026-1718
GHSA-vr85-5pwx-c6gq
Jul 07, 2026
OMERO.web must check that the JSONP callback is a valid function
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
BackgroundThere is currently no escaping or validation of the ImpactOMERO.web before 5.25.0 PatchesUsers should upgrade to 5.26.0 or higher WorkaroundsNone References
For more information If you have any questions or comments about this advisory: Open an issue in omero-web Email us at security@openmicroscopy.org Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 30 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.26.0
References
Updated Jul 07, 2026 · Source: OSV.dev
GHSA-j4gv-6x9v-v23g
Nov 24, 2025
OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Low
Network
Low
None
ImpactOMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks. PatchesUser should upgrade OMERO.web to 5.29.3 or higher. WorkaroundsNone. Resourceshttps://github.com/jquery-form/form/issues/604 Affected versions
5.10.0
5.11.0
5.11.0rc1
5.12.0
5.12.1
5.13.0
5.14.0
5.14.0rc1
5.14.1
5.15.0
5.16.0
5.17.0
+ 38 more Show less
5.18.0
5.19.0
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.23.1.dev0
5.24.0
5.25.0
5.26.0
5.27.0
5.27.1
5.27.2
5.28.0
5.29.0
5.29.1
5.29.2
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.29.3
References Updated Nov 24, 2025 · Source: OSV.dev
CVE-2020-7932
GHSA-vwxv-frj6-fhc9
PYSEC-2020-244
May 24, 2022
OMERO-web Sensitive Data Exposure
Medium
Network
Low
Low
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed. Affected versions
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
Fixed in
5.6.3
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41132
GHSA-g67g-hvc3-xmvf
PYSEC-2021-372
PYSEC-2021-379
Oct 14, 2021
Inconsistent input sanitisation leads to XSS vectors
Critical
Network
Low
None
None
BackgroundA variety of templates do not perform proper sanitization through HTML escaping.
Due to the lack of sanitization and use of ImpactOMERO.web before 5.11.0 and OMERO.figure before 4.4.1. PatchesUsers should upgrade OMERO.web to 5.11.0 or higher and OMERO.figure to 4.4.1 or higher. Affected versions
5.10.0
5.11.0rc1
5.5.dev1
5.5.dev2
5.6.0
5.6.1
5.6.2
5.6.3
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
+ 10 more Show less
5.6.dev5
5.6.dev6
5.6.dev7
5.7.0
5.7.1
5.8.0
5.8.1
5.9.0
5.9.1
5.9.2
Fixed in
5.11.0
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-21377
PYSEC-2021-32
GHSA-g4rf-pc26-6hmr
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL after performing login or switching the group context. These URLs are not validated, allowing redirection to untrusted sites. OMERO.web 5.9.0 adds URL validation before redirecting. External URLs are not considered valid, unless specified in the omero.web.redirect_allowed_hosts setting. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-21376
PYSEC-2021-31
GHSA-gfp2-w5jm-955q
Mar 23, 2021
OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0. Affected versions
5.5.dev1
5.5.dev2
5.6.dev1
5.6.dev2
5.6.dev3
5.6.dev4
5.6.dev5
5.6.dev6
5.6.dev7
5.6.0
5.6.1
5.6.2
+ 5 more Show less
5.6.3
5.7.0
5.7.1
5.8.0
5.8.1
Fixed in
5.9.0
References
Updated Nov 08, 2023 · Source: OSV.dev |