Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

commonmark — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in commonmark, with AI-generated Chinese analysis, references, and POCs.

Vendor: thephpleague

CVE ID Title CVSS Severity Published
CVE-2024-58382 league/commonmark before 2.6.0 Denial of Service via Quadratic Complexity CWE-407 7.5 High 2026-09-09
CVE-2026-86435 commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote CWE-407 7.5 High 2026-09-07
CVE-2026-86434 commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision CWE-407 7.5 High 2026-09-07
CVE-2026-86433 commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes CWE-407 7.5 High 2026-09-07
CVE-2026-86432 commonmark 2.0.0 before 2.8.4 Denial of Service via XML CWE-405 5.3 Medium 2026-09-07
CVE-2026-86430 league/commonmark before 2.9.1 Denial of Service via parsing CWE-407 7.5 High 2026-09-07
CVE-2026-86431 commonmark before 2.9.1 XSS via AttributesExtension form feed bypass CWE-79 7.2 High 2026-09-07
CVE-2026-86429 commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes CWE-407 7.5 High 2026-09-07
CVE-2026-86428 commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes CWE-407 7.5 High 2026-09-07
CVE-2026-71488 league/commonmark: Quadratic-time denial of service when parsing crafted Markdown CWE-407 7.5 High 2026-08-06
CVE-2026-71478 league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes CWE-79 6.1 Medium 2026-08-06
CVE-2026-33347 league/commonmark has an embed extension allowed_domains bypass CWE-79 9.1 - 2026-03-24
CVE-2026-30838 league/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag names CWE-79 5.4 - 2026-03-07
CVE-2025-46734 league/commonmark Cross-site Scripting vulnerability in Attributes extension CWE-79 6.4 Medium 2025-05-05

All 14 known CVE vulnerabilities affecting commonmark with full Chinese analysis, references, and POCs where available.