Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
league/commonmark: DisallowedRawHtml bypassed when a disallowed tag name ends the raw-HTML literal | Medium Risk 6.1 | 4 hours ago | 3 hours ago |
|
|
league/commonmark: Quadratic-time denial of service in the GitHub Flavored Markdown Table extension block-start scan | High Risk 7.5 | 4 hours ago | 3 hours ago |
|
|
league/commonmark's quadratic complexity bugs may lead to a denial of service | High Risk 7.5 | 1 year ago | 20 days ago |
|
|
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters | High Risk 7.5 | 28 days ago | 22 days ago |
|
|
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed | High Risk 7.2 | 28 days ago | 22 days ago |
|
|
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension | High Risk 7.5 | 28 days ago | 22 days ago |
|
|
league/commonmark: Denial of service in the SmartPunct and Attributes extensions | High Risk 7.5 | 28 days ago | 22 days ago |
|
|
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes | Medium Risk 6.1 | 1 month ago | 1 month ago |
|
|
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown | High Risk 7.5 | 1 month ago | 1 month ago |
|
|
league/commonmark: Denial of service via adjacent inline attribute blocks | High Risk 7.5 | 1 month ago | 1 month ago |
|
|
league/commonmark: Denial of service via duplicate footnote definitions | High Risk 7.5 | 1 month ago | 1 month ago |
|
|
league/commonmark: Denial of service via colliding heading slugs | High Risk 7.5 | 1 month ago | 1 month ago |
|
|
league/commonmark: Denial of service via deeply nested XML output | Medium Risk 5.3 | 1 month ago | 1 month ago |
|
|
league/commonmark has an embed extension allowed_domains bypass | Medium Risk 6.0 | 6 months ago | 6 months ago |
|
|
CommonMark has DisallowedRawHtml extension bypass via whitespace in HTML tag names | Medium Risk 6.0 | 6 months ago | 6 months ago |
|
|
league/commonmark contains a XSS vulnerability in Attributes extension | Medium Risk 6.4 | 1 year ago | 6 months ago |
|
|
PHP League CommonMark vulnerable to Cross-Site Scripting (XSS) | Medium Risk 6.1 | 4 years ago | 2 years ago |
|
|
Moderate severity vulnerability that affects league/commonmark | Medium Risk 6.1 | 7 years ago | 2 years ago |
Page 1