thephpleague
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting thephpleague.
- CVE-2024-58382league/commonmark before 2.6.0 Denial of Service via Quadratic Complexity7.5
- CVE-2026-86435commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote7.5
- CVE-2026-86434commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision7.5
- CVE-2026-86433commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes7.5
- CVE-2026-86432commonmark 2.0.0 before 2.8.4 Denial of Service via XML5.3
- CVE-2026-86431commonmark before 2.9.1 XSS via AttributesExtension form feed bypass7.2
- CVE-2026-86430league/commonmark before 2.9.1 Denial of Service via parsing7.5
- CVE-2026-86428commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes7.5
- CVE-2026-86429commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes7.5
- CVE-2026-71488league/commonmark: Quadratic-time denial of service when parsing crafted Markdown7.5
- CVE-2026-71478league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes6.1
- CVE-2026-33347league/commonmark has an embed extension allowed_domains bypass6.1
- CVE-2026-30838league/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag names6.1
- CVE-2025-46734league/commonmark Cross-site Scripting vulnerability in Attributes extension6.4
- CVE-2023-37260league/oauth2-server key exposed in exception message when passing as string and providing invalid pass phrase8.2