Krpano is a specialized panoramic and interactive image-viewer platform with a focused product footprint centered on its core krpano viewer component, which handles immersive web-based media presentation. Vulnerabilities affecting the vendor center on cross-site scripting issues stemming from improper input neutralization during web page generation, reflecting the viewer's role in rendering and displaying user-supplied or third-party content.
The number and severity of CVEs published that impact products developed by Krpano over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65892MEDIUM Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted | Nov 29, 2025 | 6.1 | 21 | NO | NO |
CVE-2020-24901MEDIUM The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test] | Jan 7, 2021 | 6.1 | 21 | NO | NO |
CVE-2020-24900MEDIUM The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml. | Jan 7, 2021 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Krpano.
Media articles that mention a CVE ID that affects a product developed by Krpano — matched by CVE ID, not by vendor name.