CVE-2020-2503: QNAP Qes

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

Affected products

  • QNAP Qes: before 2.1.1 (fixed in 2.1.1); version 2.1.1 only

Published 2020-12-24. Last modified 2026-06-17.