Vulnerabilidades em thephpleague

16 resultados
Análise Vexday

The PHP League mantém um perfil de risco moderado com 5 vulnerabilidades registradas, nenhuma sob exploração ativa no momento. A fraqueza predominante é Cross-Site Scripting (CWE-79), com apenas 1 vulnerabilidade crítica no histórico; o risco não é recente, com zero publicações nos últimos 90 dias.

CVE-2021-32708CRITICALTime-of-check Time-of-use (TOCTOU) Race Condition in league/flysystemEPSS 3.5%CVE-2023-37260HIGHleague/oauth2-server key exposed in exception message when passing as string and providing invalid pass phraseEPSS 1.0%CVE-2025-46734MEDIUMleague/commonmark Cross-site Scripting vulnerability in Attributes extensionEPSS 0.4%CVE-2026-71488HIGHleague/commonmark: Quadratic-time denial of service when parsing crafted MarkdownEPSS 0.3%CVE-2026-86429HIGHcommonmark before 2.9.1 Denial of Service via SmartPunct and AttributesEPSS 0.3%CVE-2026-86433HIGHcommonmark 1.5.0 before 2.8.4 Denial of Service via AttributesEPSS 0.3%CVE-2026-86434HIGHcommonmark 2.0.0 through 2.8.3 Denial of Service via Slug CollisionEPSS 0.3%CVE-2026-86430HIGHleague/commonmark before 2.9.1 Denial of Service via parsingEPSS 0.3%CVE-2026-86435HIGHcommonmark 1.5.0 before 2.8.4 Denial of Service via FootnoteEPSS 0.3%CVE-2026-86428HIGHcommonmark 1.5.0 before 2.10.0 Denial of Service via AttributesEPSS 0.3%CVE-2024-58382HIGHleague/commonmark before 2.6.0 Denial of Service via Quadratic ComplexityEPSS 0.3%CVE-2026-86432MEDIUMcommonmark 2.0.0 before 2.8.4 Denial of Service via XMLEPSS 0.2%CVE-2026-71478MEDIUMleague/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytesEPSS 0.2%CVE-2026-33347MEDIUMleague/commonmark has an embed extension allowed_domains bypassEPSS 0.2%CVE-2026-86431MEDIUMcommonmark before 2.9.1 XSS via AttributesExtension form feed bypassEPSS 0.2%CVE-2026-30838MEDIUMleague/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag namesEPSS 0.2%