The Drupal AJAX API does not disable JSONP by default, which can lead to cross-site scripting.
{ "constraint": ">= 8.0.0 <8.8.10" }
{ "constraint": ">= 8.9.0 <8.9.6" }
{ "constraint": ">=9.0.0 <9.0.6" }
">=7.0 <7.73 || >= 8.0.0 <8.8.10 || >= 8.9.0 <8.9.6 || >=9.0.0 <9.0.6"