League/commonmark
This hub aggregates every CVE we track for League/commonmark, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM4
Monthly trend
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 4 most recently published vulnerabilities affecting League/commonmark.
- CVE-2026-30838league/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag names6.1
- CVE-2025-46734league/commonmark Cross-site Scripting vulnerability in Attributes extension6.4
- CVE-2019-10010Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are n...6.1
- CVE-2018-20583Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_uns...6.1
Product normalization is registry-driven with AI assist and human review. How it works