CVE-2020-13890: Laborator Neon

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.

Affected products

  • Laborator Neon: from 2.0, before 2020-06-03 (fixed in 2020-06-03)

Published 2020-06-06. Last modified 2026-06-17.