commonmark
thephpleague- Software type
- —
- Catalog vulnerabilities
- 16
Severity across 14 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 14 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 16 vulnerability records affecting commonmark.
Among the 14 records analyzed by CyStack, 8 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2024-58382league/commonmark before 2.6.0 Denial of Service via Quadratic Complexity | Exploitation statusNot known exploited | FixYes | Published09/09/2026 | SeverityHigh |
CVE-2026-86435commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote | Exploitation statusNot known exploited | FixYes | Published09/07/2026 | SeverityHigh |
CVE-2026-86434commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision | Exploitation statusNot confirmed | FixYes | Published09/07/2026 | SeverityHigh |
CVE-2026-86433commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes | Exploitation statusNot known exploited | FixYes | Published09/07/2026 | SeverityHigh |
CVE-2026-86432commonmark 2.0.0 before 2.8.4 Denial of Service via XML | Exploitation statusNot known exploited | FixYes | Published09/07/2026 | SeverityMedium |
CVE-2026-86431commonmark before 2.9.1 XSS via AttributesExtension form feed bypass | Exploitation statusNot known exploited | FixYes | Published09/07/2026 | SeverityMedium |
CVE-2026-86430league/commonmark before 2.9.1 Denial of Service via parsing | Exploitation statusNot known exploited | FixYes | Published09/07/2026 | SeverityHigh |
CVE-2026-86429commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes | Exploitation statusNot confirmed | FixYes | Published09/07/2026 | SeverityHigh |
CVE-2026-86428commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes | Exploitation statusNot known exploited | FixYes | Published09/07/2026 | SeverityHigh |
CVE-2026-71488league/commonmark: Quadratic-time denial of service when parsing crafted Markdown | Exploitation statusNot known exploited | FixYes | Published08/06/2026 | SeverityHigh |
CVE-2026-71478league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes | Exploitation statusPublic exploit | FixYes | Published08/06/2026 | SeverityMedium |
CVE-2026-33347league/commonmark has an embed extension allowed_domains bypass | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityMedium |
CVE-2026-30838league/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag names | Exploitation statusNot known exploited | FixYes | Published03/07/2026 | SeverityMedium |
CVE-2025-46734league/commonmark Cross-site Scripting vulnerability in Attributes extension | Exploitation statusNot known exploited | FixNot confirmed | Published05/05/2025 | SeverityMedium |
CVE-2019-10010CVE-2019-10010 | Exploitation statusNot confirmed | FixNot confirmed | Published03/24/2019 | SeverityUnknown |
CVE-2018-20583CVE-2018-20583 | Exploitation statusNot confirmed | FixNot confirmed | Published12/30/2018 | SeverityUnknown |