Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.
https://orthanc.uclouvain.be/hg/orthanc/rev/505416b269a0
https://orthanc.uclouvain.be/hg/orthanc/file/Orthanc-1.12.2/NEWS