Thephpleague Commonmark — known CVE vulnerabilities
Every CVE whose affected-product data names Thephpleague Commonmark, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (8)
CVE-2026-86428 — CVSS 7.5 (high): commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing…
CVE-2026-86430 — CVSS 7.5 (high): league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link…
CVE-2026-86429 — CVSS 7.5 (high): The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its…
CVE-2026-86431 — CVSS 7.2 (high): league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the…
CVE-2026-33347 — CVSS 6.1 (medium): league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension…
CVE-2026-30838 — CVSS 6.1 (medium): league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline…
CVE-2019-10010 — CVSS 6.1 (medium): Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links…
CVE-2018-20583 — CVSS 6.1 (medium): Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote…