CVE-2020-36324: Wikimedia Analytics-Quarry-Web

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Wikimedia Quarry analytics-quarry-web before 2020-12-15 allows Reflected XSS because app.py does not explicitly set the application/json content type.

Affected products

  • Wikimedia Analytics-Quarry-Web: before 2020-12-15 (fixed in 2020-12-15)

Published 2021-04-21. Last modified 2026-06-17.