Search CVE reports


Toggle filters

1 – 3 of 3 results


CVE-2026-33347

Medium priority

Some fixes available 3 of 5

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Vulnerable Fixed Fixed Fixed
Show less packages

CVE-2026-30838

Medium priority

Some fixes available 3 of 4

league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Fixed Fixed Fixed
Show less packages

CVE-2025-46734

Medium priority

Some fixes available 3 of 5

league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Not affected Fixed Fixed Fixed
Show less packages