CVE-2020-18702: Quokka Project Quokka
Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.
Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'.
Affected products
- Quokka Project Quokka: version 0.4.0 only
Published 2021-08-16. Last modified 2026-06-17.