OMERO.web uses jquery-form library, which may be vulnerable to XSS attack
Description
Published to the GitHub Advisory Database
Nov 24, 2025
Reviewed
Nov 24, 2025
Last updated
Nov 24, 2025
Impact
OMERO.web uses the jquery-form library throughout to handle form submission and response processing. Due to some unpatched potential vulnerabilities in jquery-form, OMERO.web 5.29.2 and earlier may be susceptible to XSS attacks.
Patches
User should upgrade OMERO.web to 5.29.3 or higher.
Workarounds
None.
Resources
jquery-form/form#604
References