{"id":"CVE-2020-13258","aliases":["GHSA-g5j6-r3x9-gf2m","PYSEC-2026-626"],"title":"Cross-site scripting in Contentful","summary":"Cross-site scripting in Contentful","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","vendor":"contentful","product":"contentful","ecosystem":"pip","affected":["contentful < 1.12.4"],"patched":["contentful 1.12.4"],"published":"2021-06-18","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-g5j6-r3x9-gf2m","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13258"},{"url":"https://github.com/contentful/the-example-app.py/issues/44"}],"tags":["osv","pip","exploit-available"],"epss":0.02063,"epssPercentile":0.80246,"ingestedAt":"2026-07-08T18:25:49.231Z","exploits":{"nuclei":["CVE-2020-13258"],"checkedAt":"2026-09-21T15:24:03.153Z"},"exploitAvailable":true,"slug":"CVE-2020-13258","body":"## Overview\n\nContentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py.\n\n## Affected packages\n\n- `contentful < 1.12.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `contentful 1.12.4`","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":33.6,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[{"seq":4486,"id":"CVE-2020-13258","ts":1788887183811,"field":"exploit_available","old":"false","new":"true"},{"seq":3369,"id":"CVE-2020-13258","ts":1788886302643,"field":"exploit_available","old":"true","new":"false"},{"seq":2224,"id":"CVE-2020-13258","ts":1788882972302,"field":"exploit_available","old":"false","new":"true"},{"seq":1253,"id":"CVE-2020-13258","ts":1788882383903,"field":"exploit_available","old":"true","new":"false"},{"seq":367,"id":"CVE-2020-13258","ts":1788881819272,"field":"exploit_available","old":"false","new":"true"}]}