Skip to main content

Vendor archive

thephpleague CVEs

Beta · best-effort

6 CVEs tagged to vendor thephpleague1 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-33347

Published Mar 24, 2026

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-30838

Published Mar 7, 2026

league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace characte…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-37260

Published Jul 6, 2023

league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2 and prior to version 8.5.3, servers that passed their keys…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10010

Published Mar 24, 2019

Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML e…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20583

Published Dec 30, 2018

Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1