Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.28% | — | Thephpleague CommonmarkAI | 9/9/2026 | 9/9/2026 | league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs designed to trigger worst-case performance, and sending multiple requests in parallel exhausts CPU… | |
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Thephpleague CommonmarkAI | 7/9/2026 | 9/9/2026 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to… | |
| Pendiente de análisis | Alta (8.7) | 0.51% | — | Thephpleague CommonmarkAI | 7/9/2026 | 8/9/2026 | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning. Unauthenticated attackers can submit approximately 32 KB of repeated attribute blocks to cause parsing to… | |
| Pendiente de análisis | Media (6.9) | 0.42% | — | Thephpleague CommonmarkAI | 7/9/2026 | 10/9/2026 | commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory consumption and output amplification, exhausting server resources. | |
| Analizada | Media (6.9) | 0.39% | — | Thephpleague Commonmark | 7/9/2026 | 9/9/2026 | league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte (e.g. {\x0Conclick="alert(1)"}) bypasses the AttributesHelper::filterAttributes() 'on*' event-handler filter… | |
| Analizada | Alta (8.7) | 0.49% | — | Thephpleague Commonmark | 7/9/2026 | 10/9/2026 | league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested… | |
| Analizada | Alta (8.7) | 0.49% | — | Thephpleague Commonmark | 7/9/2026 | 9/9/2026 | commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU… | |
| Pendiente de análisis | Alta (8.7) | 0.51% | — | Thephpleague CommonmarkAI | 7/9/2026 | 19/9/2026 | league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The… | |
| Analizada | Alta (8.7) | 0.52% | — | Thephpleague Commonmark | 7/9/2026 | 19/9/2026 | The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Thephpleague CommonmarkAI | 6/8/2026 | 10/9/2026 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character… | |
| Pendiente de análisis | Media (6.1) | 0.36% | — | Thephpleague CommonmarkAI | 6/8/2026 | 10/9/2026 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers… | |
| Aplazada | Media (5.1) | 0.31% | — | Milkdown Preset CommonmarkAITennisconnect ComponentsAI | 24/7/2026 | 27/7/2026 | Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rendered link. The… | |
| Analizada | Media (6.3) | 0.32% | — | Thephpleague Commonmark | 24/3/2026 | 17/6/2026 | league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the… | |
| Analizada | Media (5.1) | 0.24% | — | Thephpleague Commonmark | 7/3/2026 | 17/6/2026 | league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. For example, <script\n> would pass through unfiltered and be rendered as a valid… | |
| Aplazada | Media (6.4) | 0.38% | — | Thephpleague CommonmarkAI | 5/5/2025 | 17/6/2026 | league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls into HTML. The league/commonmark library provides configuration options such as… | |
| Modificada | Crítica (9.8) | 1.5% | — | Github Cmark-gfmGjtorikian Commonmarker | 4/1/2024 | 14/7/2026 | CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more… | |
| Modificada | Media (6.1) | 1.1% | — | Thephpleague Commonmark | 24/3/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are not properly escaped during rendering, a different vulnerability than CVE-2018-20583. | |
| Modificada | Media (6.1) | 1.6% | — | Thephpleague Commonmark | 30/12/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML (even if allow_unsafe_links is false) via a newline character (e.g., writing javascript as javascri%0apt). |