SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2020-13671

HIGH · CVSS 8.8 EPSS 4.30% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-11-20 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Unknown

Added to KEV: 2022-01-18

Required action: Apply updates per vendor instructions.

CVE
CVE-2020-13671
Severity
HIGH
CVSS
8.8
EPSS
4.30%

Original NVD Description

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

Related CVEs

Other vulnerabilities affecting the same vendor(s)