VDB

CVE-2020-13672

CVE-2020-13672 PUBLISHED

Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. This issue affects: Drupal Core 9.1.x versions prior to 9.1.7; 9.0.x versions prior to 9.0.12; 8.9.x versions prior to 8.9.14; 7.x versions prior to 7.80.

EPSS 0.55% · 68.4th percentile

Risk Scores

EPSS Score
0.55%
68.4th percentile

Affected Products

VendorProductVersions
Bitnamidrupal0, 9.0.0, 9.1.0
Bitnamidrupal9.0.0, 9.1.0, 8.9.0

Timeline

  • Apr 21, 2021 CVE Published
  • Feb 12, 2022 EPSS Score
  • Apr 5, 2022 EPSS Score
  • May 27, 2022 EPSS Score
  • Jul 20, 2022 EPSS Score
  • Sep 10, 2022 EPSS Score
  • Dec 23, 2022 EPSS Score
  • Feb 14, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 7, 2023 EPSS Score
  • May 29, 2023 EPSS Score
  • Jul 20, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›