Drupal has released security advisories to address multiple vulnerabilities in Drupal Core. A remote attacker may send specially crafted HTTP requests or entice a system administrator into opening a specially crafted web page to exploit the vulnerabilities.
Please note that Drupal 8 prior to version 8.8.x has reached its End-Of-Life (EOL). No security updates will be provided after that. Users should arrange upgrading the Drupal to supported versions or migrating to other supported technology.
Depending on the vulnerability being exploited, a successful attack could lead to remote code execution, cross site scripting, or validation bypass on an affected system.
The product vendor has released patches to address the issues.
https://www.drupal.org/sa-core-2020-004
https://www.drupal.org/sa-core-2020-005
https://www.drupal.org/sa-core-2020-006
https://www.drupal.org/core/release-cycle-overview
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13663
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13664
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13665