CVE-2020-36827

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.

Published 2024-03-24. Last modified 2026-06-17.