Several moderately critical and critical bugs are found in Drupal core
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2020-007
Project: Drupal core
Date: 2020-September-16
Security risk: Moderately critical 14∕25
Vulnerability: Cross-site scripting
CVE IDs: CVE-2020-13666
Description
The Drupal AJAX API does not disable JSONP by default, which can lead to cross-site scripting.
Solution
Install the latest version: