Description XWiki Platform before 12.8 mishandles escaping in the property displayer. Remediation References CVE-2020-13654 Related Vulnerabilities WordPress Plugin Rent-A-Car TimThumb Arbitrary File Upload (1.0) Drupal Core 4.7.x Arbitrary Code Execution (4.7.0) Drupal Core 8.8.x Multiple Cross-Site Scripting Vulnerabilities (8.8.0 - 8.8.9) WordPress Plugin Kraken.io Image Optimizer Cross-Site Request Forgery (2.6.5) Magento Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-9577) Severity High Classification CVE-2020-13654 CWE-116 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Tags Missing Update Known Vulnerabilities