CVE-2020-24901: Krpano
Medium severity, CVSS 6.1. EPSS: 4.1% chance of exploitation in the next 30 days.
The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test].url.
Affected products
- Krpano Krpano: up to and including 1.20.8
Published 2021-01-07. Last modified 2026-06-17.