VulnSea

league has 10 CVEs on record. Disclosure cadence is accelerating: 10 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 6. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-407 (7) and CWE-1050 (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
10 prev 0

Products

  • league/commonmark 10
10
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

league vulnerabilities

CVEs affecting league, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

GHSA-j8pm-gj4c-rq4xHigh· 7.5
3w ago

league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters

league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters

Twilightleague · league/commonmarkvia GHSA
GHSA-f8fg-pg57-v4j8High· 7.2
3w ago

league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed

league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed

Twilightleague · league/commonmarkvia GHSA
GHSA-jjv6-8j6v-6j52High· 7.5
3w ago

league/commonmark: Denial of service in the SmartPunct and Attributes extensions

league/commonmark: Denial of service in the SmartPunct and Attributes extensions

Twilightleague · league/commonmarkvia GHSA
GHSA-8rr7-cvq3-gmfhHigh· 7.5
3w ago

league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension

league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension

Twilightleague · league/commonmarkvia GHSA
CVE-2026-71478Medium· 6.1
1mo ago

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage retur…

Sunlitleague · league/commonmarkEPSS 0.25%via NVD
CVE-2026-71488High· 7.5
1mo ago

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing pa…

Twilightleague · league/commonmarkEPSS 0.35%via NVD
GHSA-g2gp-3wwq-f4phHigh· 7.5
1mo ago

league/commonmark: Denial of service via adjacent inline attribute blocks

league/commonmark: Denial of service via adjacent inline attribute blocks

Twilightleague · league/commonmarkvia GHSA
GHSA-jfm3-95jq-q3rfHigh· 7.5
1mo ago

league/commonmark: Denial of service via duplicate footnote definitions

league/commonmark: Denial of service via duplicate footnote definitions

Twilightleague · league/commonmarkvia GHSA
GHSA-mh25-x5hq-wrqpHigh· 7.5
1mo ago

league/commonmark: Denial of service via colliding heading slugs

league/commonmark: Denial of service via colliding heading slugs

Twilightleague · league/commonmarkvia GHSA
GHSA-mj63-m3rc-8pprMedium· 5.3
1mo ago

league/commonmark: Denial of service via deeply nested XML output

league/commonmark: Denial of service via deeply nested XML output

Sunlitleague · league/commonmarkvia GHSA
league vulnerabilities (CVEs) · VulnSea