CVE-2020-13756
37Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actepss 55%
from disclosure to weapon
Published on NVDJun 3
VulnCheck+588d
exploitation probability
55%top 1% of all CVEs
observed exploitation
yesVulnCheck
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.
Affected products
n/a · n/aReferences
http://packetstormsecurity.com/files/157923/Sabberworm-PHP-CSS-Code-Injection.htmlhttp://seclists.org/fulldisclosure/2020/Jun/7https://github.com/sabberworm/PHP-CSS-Parser/commit/2ebf59e8bfbf6cfc1653a5f0ed743b95062c62a4https://github.com/sabberworm/PHP-CSS-Parser/releases/tag/8.3.1https://lists.debian.org/debian-lts-announce/2025/10/msg00013.html