VendorsThephpleaguecommonmarkany version
Vulnerabilities

Thephpleague (The League of Extraordinary Packages) CommonMark any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-86429
commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes
Published 2026-09-07 · Analyzed
8.7EPSS 0.005
CVE-2026-86428
commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes
Published 2026-09-07 · Analyzed
8.7EPSS 0.005
CVE-2026-86430
league/commonmark before 2.9.1 Denial of Service via parsing
Published 2026-09-07 · Analyzed
8.7EPSS 0.005
CVE-2026-86431
commonmark before 2.9.1 XSS via AttributesExtension form feed bypass
Published 2026-09-07 · Analyzed
7.2EPSS 0.004
CVE-2026-33347
league/commonmark has an embed extension allowed_domains bypass
Published 2026-03-24 · Analyzed
6.3EPSS 0.003
CVE-2018-20583
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as javascri%0apt).
Published 2018-12-30 · Modified
6.1EPSS 0.016
CVE-2019-10010
Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are not properly escaped during rendering, a different vulnerability than CVE-2018-20583.
Published 2019-03-24 · Modified
6.1EPSS 0.011
CVE-2026-30838
league/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag names
Published 2026-03-07 · Analyzed
6.1EPSS 0.002