Thephpleague / Commonmark
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-58382 | league/commonmark before 2.6.0 Denial of Service via Quadratic Complexity | HIGH | 8.7 | Sep 9, 2026 |
| CVE-2026-86435 | commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote | HIGH | 8.7 | Sep 7, 2026 |
| CVE-2026-86434 | commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision | HIGH | 8.7 | Sep 7, 2026 |
| CVE-2026-86433 | commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes | HIGH | 8.7 | Sep 7, 2026 |
| CVE-2026-86432 | commonmark 2.0.0 before 2.8.4 Denial of Service via XML | MEDIUM | 6.9 | Sep 7, 2026 |
| CVE-2026-86431 | commonmark before 2.9.1 XSS via AttributesExtension form feed bypass | MEDIUM | 6.9 | Sep 7, 2026 |
| CVE-2026-86430 | league/commonmark before 2.9.1 Denial of Service via parsing | HIGH | 8.7 | Sep 7, 2026 |
| CVE-2026-86429 | commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes | HIGH | 8.7 | Sep 7, 2026 |
| CVE-2026-86428 | commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes | HIGH | 8.7 | Sep 7, 2026 |
| CVE-2026-71488 | league/commonmark: Quadratic-time denial of service when parsing crafted Markdown | HIGH | 7.5 | Aug 6, 2026 |
| CVE-2026-71478 | league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes | MEDIUM | 6.1 | Aug 6, 2026 |
| CVE-2026-33347 | league/commonmark has an embed extension allowed_domains bypass | MEDIUM | 6.3 | Mar 24, 2026 |
| CVE-2026-30838 | league/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag names | MEDIUM | 5.1 | Mar 7, 2026 |
| CVE-2025-46734 | league/commonmark Cross-site Scripting vulnerability in Attributes extension | MEDIUM | 6.4 | May 5, 2025 |
| CVE-2019-10010 | Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using d… | MEDIUM | 6.1 | Mar 24, 2019 |
| CVE-2018-20583 | Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert un… | MEDIUM | 6.1 | Dec 30, 2018 |
Showing 1 to 16 of 16 CVEs