thephpleague
- Products in analyzed data
- 1
- Catalog vulnerabilities
- 18
Severity across 14 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 14 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, thephpleague recorded 11 security vulnerabilities in the last 90 days across 1 products, including 8 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, commonmark had the most security vulnerabilities in the thephpleague ecosystem, with 11 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2024-58382league/commonmark before 2.6.0 Denial of Service via Quadratic Complexity | Exploitation statusNot known exploited | FixYes | Affected productcommonmark | Published09/09/2026 | SeverityHigh |
CVE-2026-86435commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote | Exploitation statusNot known exploited | FixYes | Affected productcommonmark | Published09/07/2026 | SeverityHigh |
CVE-2026-86434commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision | Exploitation statusNot confirmed | FixYes | Affected productcommonmark | Published09/07/2026 | SeverityHigh |
CVE-2026-86433commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes | Exploitation statusNot known exploited | FixYes | Affected productcommonmark | Published09/07/2026 | SeverityHigh |
CVE-2026-86432commonmark 2.0.0 before 2.8.4 Denial of Service via XML | Exploitation statusNot known exploited | FixYes | Affected productcommonmark | Published09/07/2026 | SeverityMedium |
CVE-2026-86431commonmark before 2.9.1 XSS via AttributesExtension form feed bypass | Exploitation statusNot known exploited | FixYes | Affected productcommonmark | Published09/07/2026 | SeverityMedium |
CVE-2026-86430league/commonmark before 2.9.1 Denial of Service via parsing | Exploitation statusNot known exploited | FixYes | Affected productcommonmark | Published09/07/2026 | SeverityHigh |
CVE-2026-86429commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes | Exploitation statusNot confirmed | FixYes | Affected productcommonmark | Published09/07/2026 | SeverityHigh |
CVE-2026-86428commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes | Exploitation statusNot known exploited | FixYes | Affected productcommonmark | Published09/07/2026 | SeverityHigh |
CVE-2026-71488league/commonmark: Quadratic-time denial of service when parsing crafted Markdown | Exploitation statusNot known exploited | FixYes | Affected productcommonmark | Published08/06/2026 | SeverityHigh |
CVE-2026-71478league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes | Exploitation statusPublic exploit | FixYes | Affected productcommonmark | Published08/06/2026 | SeverityMedium |
CVE-2026-33347league/commonmark has an embed extension allowed_domains bypass | Exploitation statusNot known exploited | FixYes | Affected productcommonmark | Published03/24/2026 | SeverityMedium |
CVE-2026-30838league/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag names | Exploitation statusNot known exploited | FixYes | Affected productcommonmark | Published03/07/2026 | SeverityMedium |
CVE-2025-46734league/commonmark Cross-site Scripting vulnerability in Attributes extension | Exploitation statusNot known exploited | FixNot confirmed | Affected productcommonmark | Published05/05/2025 | SeverityMedium |
CVE-2023-37260league/oauth2-server key exposed in exception message when passing as string and providing invalid pass phrase | Exploitation statusNot known exploited | FixNot confirmed | Affected productoauth2-server | Published07/06/2023 | SeverityHigh |
CVE-2021-32708Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem | Exploitation statusNot confirmed | FixNot confirmed | Affected productflysystem | Published06/24/2021 | SeverityCritical |
CVE-2019-10010CVE-2019-10010 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published03/24/2019 | SeverityUnknown |
CVE-2018-20583CVE-2018-20583 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published12/30/2018 | SeverityUnknown |