CVE-2020-13676
The QuickEdit module does not properly check access to fields…
Drupal's JSON:API and REST/File modules allow file uploads through their…
Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails…
Information Disclosure vulnerability in file module of Drupal Core allows…
Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows…
Cross-site scripting vulnerability in Drupal Core. Drupal AJAX API does…
Access bypass vulnerability in Drupal Core allows JSON:API when JSON:API…