CVE-2020-13669

Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.


We have discovered 24,590 live websites that are affected by CVE-2020-13669.

Test my site




Affected Software

Product  Drupal
Category Content Management System
Vulnerable Domains24,590 live websites (9.79% of Drupal install base)
Vulnerable Versions
  • from 8.8 before 8.8.10
  • from 8.9 before 8.9.6
  • from 9 before 9.0.6
Vulnerable Versions Count21 versions ( 6.89% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Feb 11, 2022
  • Updated - Aug 4, 2024

CVE-2020-13669 usage by Country

United States9,352 websites



Germany3,632 websites
France2,046 websites
Belgium1,131 websites
Russia967 websites
Netherlands719 websites
GB577 websites
Italy447 websites
Switzerland408 websites
Spain387 websites

CVE-2020-13669 usage by TLD

.com6,461 websites
.org2,446 websites
.de2,336 websites
.be1,164 websites
.fr1,008 websites
.edu796 websites
.ru787 websites
.nl647 websites
.net542 websites
.it474 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-13669

Top websites that are affected by CVE-2020-13669. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.**.uk United States***
***.org United States*,***
*****.com United States*,***
**************.ie Ireland*,***
*********.****.fr France*,***
*******.org United States*,***
****.com United States*,***
***********.org United States*,***
*********.ca United States*,***
************.com United States*,***
See full domain list

FAQ

CVE-2020-13669 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Drupal
A total of 24,590 websites have been identified as vulnerable to CVE-2020-13669, discovered through global website indexing conducted by WebTechSurvey.
Drupal is susceptible to CVE-2020-13669 vulnerability.
Drupal versions before 9.0.6 are vulnerable to CVE-2020-13669.
Version 9.0.6 of Drupal addresses the CVE-2020-13669 security vulnerability.