The PHP League maintains a small collection of widely embedded open-source libraries and frameworks, including CommonMark, Flysystem, and OAuth2 implementations, that serve as critical building blocks for PHP applications across the web. Its vulnerabilities recur through application-layer weakness classes including cross-site scripting, improper input validation, SSRF, server configuration disclosure, and race conditions in authentication and file-handling logic—flaws typical of libraries that process user input or mediate security-sensitive operations. Defenders should track this vendor's releases closely despite its narrow product count, since remediation often depends on downstream framework and application maintainers rebuilding against patched versions; live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thephpleague over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32708HIGH Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this c | Jun 24, 2021 | 8.1 | 26 | NO | NO |
CVE-2026-30838MEDIUM league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character | Mar 7, 2026 | 6.1 | 22 | NO | NO |
CVE-2018-20583MEDIUM Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library versions 0.15.6 through 0.18.x before 0.18.1 allows remote attackers to insert unsafe URLs into HTML ( | Dec 30, 2018 | 6.1 | 22 | NO | NO |
CVE-2023-37260HIGH league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2 and prior to version 8.5.3, servers that passed their keys | Jul 6, 2023 | 7.5 | 21 | NO | NO |
CVE-2019-10010MEDIUM Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML en | Mar 24, 2019 | 6.1 | 21 | NO | NO |
CVE-2026-33347MEDIUM league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due t | Mar 24, 2026 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thephpleague.
Media articles that mention a CVE ID that affects a product developed by Thephpleague — matched by CVE ID, not by vendor name.