Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10 V contain certain field types that do not properly sanitize data from non-form sources, which can lead to arbitrary PHP code execution in some cases.
id: CVE-2019-6340
info:
name: Drupal - Remote Code Execution
author: madrobot
severity: high
...