CVE-2024-42020: Veeam One

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.

Affected products

  • Veeam One: from 12, up to and including 12.1.0.3208

Published 2024-09-07. Last modified 2026-06-17.