← Vulnerability feed

Vulnerability record · CVE-2017-6920 · published 6 August 2018

CVE-2017-6920: Drupal vulnerability

DDrupal · Drupal

Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.

9.8 CVSS 3.0 Critical EPSS 20% · top 2.6% CWE-19 · CWE-19
9.8CVSS 3.0 base score, v2 7.5
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6920 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-9082Drupal core SQL injection in unauthenticated request pathDrupal core contains a SQL injection flaw (CWE-89) caused by improper neutralization of special elements in SQL commands. It affects multiple core br…KEVEPSS 16%analysed9.8CVE-2018-7602Drupal Core Remote Code Execution via Multiple SubsystemsCVE-2018-7602 is a remote code execution flaw in multiple subsystems of Drupal 7.x and 8.x, related to SA-CORE-2018-002. It allows an attacker to com…KEVEPSS 99%analysed9.8CVE-2018-7600Drupal Core input validation flaw enables remote code executionDrupal core before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 fails to properly validate input across multiple subsystems, al…KEVEPSS 100%analysed8.8CVE-2020-13671Drupal core filename sanitization flaw allows uploaded files to execute as PHPDrupal core fails to properly sanitize certain filenames on uploaded files, so files can be interpreted with the wrong extension and served as the wr…KEVEPSS 35%analysed8.1CVE-2019-6340Drupal Core field types fail to sanitize non-form data, enabling PHP code executionSome field types in Drupal 8.5.x before 8.5.11 and 8.6.x before 8.6.10 do not properly sanitize data arriving from non-form sources, which can lead t…KEVEPSS 92%analysed7.8CVE-2020-28949PEAR Archive_Tar stream-wrapper filename sanitization bypass allows file writeArchive_Tar through 1.4.10 only sanitizes '://' filenames to block phar attacks, so other stream wrappers such as file:// still pass through and can …KEVEPSS 85%analysed7.5CVE-2020-36193PEAR Archive_Tar path traversal via symlink handlingTar.php in Archive_Tar through 1.4.11 fails to adequately check symbolic links, allowing write operations to escape the intended extraction directory…KEVEPSS 71%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed

Source: NIST National Vulnerability Database (record CVE-2017-6920), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.