CVE-2026-33347
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
- EPSS probability
- 0.24%
- CWE
- CWE-79, CWE-185, CWE-918
- Published
- 2026-03-24
- Last modified
- 2026-03-26
Affected products
- thephpleague commonmark
Weakness type
Related vulnerabilities
- CVE-2026-81635 — A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an...
- CVE-2026-0308 — PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
- CVE-2026-85645 — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting
- CVE-2026-76562 — Sidebar Manager Light <= 1.18 - Unauthenticated Stored Cross-Site Scripting via 'sbm_description' Parameter
- CVE-2026-4657 — Easy Google Fonts <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via control_selectors Meta Field
- CVE-2026-15820 — Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Module 'attributes' Setting
- CVE-2026-15796 — Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_video_service_url' Setting
- CVE-2026-87870 — Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via REST API Parameters