CVE-2020-24900: Krpano
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.
Affected products
- Krpano Krpano: up to and including 1.20.8
Published 2021-01-07. Last modified 2026-06-17.