Quokka ProjectCVEs & Vulnerabilities
3 CVEs affecting Quokka Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
quokka 3
CVE-2020-18705CRITICAL
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.
16 Aug 2021
9.8
CVSS
CVE-2020-18703CRITICAL
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.
16 Aug 2021
9.8
CVSS
CVE-2020-18702MEDIUM
Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'.
16 Aug 2021
6.1
CVSS
← PrevPage 1 / 1Next →