In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
Source: NVD ↗ · CISA KEV Catalog ↗