Sabberworm maintains a narrowly scoped PHP CSS parsing library used for style-sheet manipulation and analysis in web applications. The vendor's vulnerability history centers on code-injection flaws arising from insufficient input validation in the parser, a characteristic risk in libraries that process and transform structured data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sabberworm over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13756CRITICAL Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is c | Jun 3, 2020 | 9.8 | 57 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sabberworm.
Media articles that mention a CVE ID that affects a product developed by Sabberworm — matched by CVE ID, not by vendor name.