CVE-2020-18702: Quokka Project Quokka

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'.

Affected products

Published 2021-08-16. Last modified 2026-06-17.