CVE-2020-13672: Drupal

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. This issue affects: Drupal Core 9.1.x versions prior to 9.1.7; 9.0.x versions prior to 9.0.12; 8.9.x versions prior to 8.9.14; 7.x versions prior to 7.80.

Affected products

  • Drupal Drupal: before 7.80 (fixed in 7.80); from 8.9.0, before 8.9.14 (fixed in 8.9.14); from 9.0.0, before 9.0.12 (fixed in 9.0.12); from 9.1.0, before 9.1.7 (fixed in 9.1.7)

Published 2022-02-11. Last modified 2026-06-17.