Skip to main content

Vendor/product archive

thephpleague / commonmark CVEs

Beta · best-effort

4 CVEs tagged to thephpleague / commonmark0 Critical, 0 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-33347

Published Mar 24, 2026

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-30838

Published Mar 7, 2026

league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace characte…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-10010

Published Mar 24, 2019

Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML e…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20583

Published Dec 30, 2018

Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1