← Back

Krpano

krpano

Vendor: Krpano • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Krpano
1Krpano
Jun 17, 2026
Nov 29, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted URL to the passQueryParameters function...Show more
Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted URL to the passQueryParameters function with the xml parameter enabled.Show less
1Krpano
1Krpano
Jun 17, 2026
Jan 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test].url.
1Krpano
1Krpano
Jun 17, 2026
Jan 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.