CVE-2020-24900: Krpano

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.

Affected products

  • Krpano Krpano: up to and including 1.20.8

Published 2021-01-07. Last modified 2026-06-17.