thephpleague
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 29, 2018 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →commonmark before 2.9.1 XSS via AttributesExtension form feed bypass
league/commonmark before 2.9.1 Denial of Service via parsing
commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes
commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes
league/commonmark has an embed extension allowed_domains bypass
league/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag names
league/oauth2-server key exposed in exception message when passing as string and providing invalid pass phrase
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
Monitor thephpleague in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.