Thephpleague
Thephpleague Commonmark: vulnerabilidades y CVE
Thephpleague Commonmark tiene 16 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses13
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-58382 | Alta (8.7) | 0.28% | — | 9 sept 2026 | league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs… |
| CVE-2026-86435 | Alta (8.7) | 0.49% | — | 7 sept 2026 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote… |
| CVE-2026-86433 | Alta (8.7) | 0.51% | — | 7 sept 2026 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning.… |
| CVE-2026-86432 | Media (6.9) | 0.42% | — | 7 sept 2026 | commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST… |
| CVE-2026-86431 | Media (6.9) | 0.39% | — | 7 sept 2026 | league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte (e.g.… |
| CVE-2026-86430 | Alta (8.7) | 0.49% | — | 7 sept 2026 | league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on… |
| CVE-2026-86428 | Alta (8.7) | 0.49% | — | 7 sept 2026 | commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct… |
| CVE-2026-86434 | Alta (8.7) | 0.51% | — | 7 sept 2026 | league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision,… |
| CVE-2026-86429 | Alta (8.7) | 0.52% | — | 7 sept 2026 | The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly… |
| CVE-2026-71488 | Alta (7.5) | 0.63% | — | 6 ago 2026 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because… |
| CVE-2026-71478 | Media (6.1) | 0.36% | — | 6 ago 2026 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a… |
| CVE-2026-33347 | Media (6.3) | 0.32% | — | 24 mar 2026 | league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion… |
| CVE-2026-30838 | Media (5.1) | 0.24% | — | 7 mar 2026 | league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and… |
| CVE-2025-46734 | Media (6.4) | 0.36% | — | 5 may 2025 | league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert… |
| CVE-2019-10010 | Media (6.1) | 1.1% | — | 24 mar 2019 | Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are not properly escaped… |
| CVE-2018-20583 | Media (6.1) | 1.6% | — | 30 dic 2018 | Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false)… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.