Thephpleague

Commonmark

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 07.09.2026 12:53:49
  • Zuletzt bearbeitet 08.10.2026 16:17:56

commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-tim...

  • EPSS 0.35%
  • Veröffentlicht 06.08.2026 22:18:31
  • Zuletzt bearbeitet 10.09.2026 20:41:33

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedl...

  • EPSS 0.2%
  • Veröffentlicht 06.08.2026 22:18:31
  • Zuletzt bearbeitet 10.09.2026 20:41:33

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed,...

  • EPSS 0.24%
  • Veröffentlicht 24.03.2026 19:26:23
  • Zuletzt bearbeitet 08.04.2026 19:01:50

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. ...

  • EPSS 0.22%
  • Veröffentlicht 07.03.2026 16:00:32
  • Zuletzt bearbeitet 11.03.2026 20:24:06

league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. For example, <s...

  • EPSS 0.33%
  • Veröffentlicht 05.05.2025 19:52:59
  • Zuletzt bearbeitet 15.04.2026 00:35:42

league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls into HTML....

Exploit
  • EPSS 1.05%
  • Veröffentlicht 24.03.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:18:12

Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are not properly escaped during rendering, a different vul...

Exploit
  • EPSS 1.6%
  • Veröffentlicht 30.12.2018 05:29:00
  • Zuletzt bearbeitet 21.11.2024 04:01:47

Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., wr...