CVE-2020-13671

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.


We have discovered 110,467 live websites that are affected by CVE-2020-13671.

Run a Free Instant Scan




Affected Software

Product  Drupal
Category Content Management System
Vulnerable Domains110,467 live websites (54% of Drupal install base)
Vulnerable Versions
  • from 0 through 9.0.8
Vulnerable Versions Count128 versions ( 37% of all versions)



Details

  • Published - Nov 20, 2020
  • Updated - Oct 21, 2025

Website Distribution by Country

Number of websites using CVE-2020-13671
United States28,243 websites



Germany10,613 websites
Russia10,244 websites
France8,374 websites
Italy4,147 websites
GB3,947 websites
Belgium3,632 websites
Spain3,047 websites
Netherlands2,837 websites
Canada2,776 websites

Website Distribution by TLD

Number of websites using CVE-2020-13671
.com30,032 websites
.org9,217 websites
.ru8,245 websites
.de6,198 websites
.fr4,125 websites
.be3,416 websites
.it3,038 websites
.net2,731 websites
.nl2,197 websites
.edu1,979 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-13671

Top websites that are affected by CVE-2020-13671. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.gov United States*,***
***.**.gov United States*,***
****.org United States*,***
*******.com United States*,***
******.org United States*,***
*******.org United States*,***
*****************.org United States*,***
*******.org United States*,***
***************.********.gov United States*,***
*****.org United States*,***
See full domain list

FAQ

A total of 110,467 websites have been identified as vulnerable to CVE-2020-13671, based on global website indexing conducted by WebTechSurvey.
The Drupal is affected by the CVE-2020-13671 vulnerability.
Drupal versions up to and including 9.0.8 are vulnerable to CVE-2020-13671.