CVE-2020-13663: Drupal

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.

Affected products

  • Drupal Drupal: from 7.0, before 7.72 (fixed in 7.72); from 8.8.0, before 8.8.8 (fixed in 8.8.8); from 8.9.0, before 8.9.1 (fixed in 8.9.1); from 9.0.0, before 9.0.1 (fixed in 9.0.1)

Published 2021-06-11. Last modified 2026-06-17.