CVE-2020-24901: Krpano

Medium severity, CVSS 6.1. EPSS: 4.1% chance of exploitation in the next 30 days.

The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test].url.

Affected products

  • Krpano Krpano: up to and including 1.20.8

Published 2021-01-07. Last modified 2026-06-17.