Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
Packagist/league/commonmark — 5 CVEs · VulnScope
pkg:Packagist/
league/commonmark
5 total CVEs
MEDIUM
5
✅ Check your installed version
Check
All known vulnerabilities
MEDIUM
6.4
CVE-2025-46734
league/commonmark contains a XSS vulnerability in Attributes extension
>= 1.5.0, < 2.7.0
MEDIUM
6.1
CVE-2026-33347
league/commonmark has an embed extension allowed_domains bypass
>= 2.3.0, < 2.8.2
MEDIUM
6.1
CVE-2026-30838
CommonMark has DisallowedRawHtml extension bypass via whitespace in HTML tag names
>= 2.0.0, < 2.8.1
MEDIUM
6.1
CVE-2018-20583
PHP League CommonMark vulnerable to Cross-Site Scripting (XSS)
>= 0.15.6, < 0.18.1
MEDIUM
6.1
Moderate severity vulnerability that affects league/commonmark
from 0, < 0.18.3
CVE-2019-10010