Description
Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6.
Remediation
References
Related Vulnerabilities
WordPress Plugin Media Library Assistant Multiple Vulnerabilities (2.81)
Drupal Core 8.9.x Information Disclosure (8.9.0 - 8.9.5)
Nginx Improper Encoding or Escaping of Output Vulnerability (CVE-2013-4547)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5293)
WordPress Plugin No Follow All External Links Spam Injection (2.3.0)