CVE-2020-26701: Kaaproject Kaa
Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in Dashboards section in Kaa IoT Platform v1.2.0 allows remote attackers to inject malicious web scripts or HTML Injection payloads via the Description parameter.
Affected products
- Kaaproject Kaa: version 1.2.0 only
Published 2020-11-17. Last modified 2026-06-17.