CVE-2026-71478 | PHP League Commonmark up to 2.8.3 AttributesExtension cross site scripting (Nessus ID 333351)
A vulnerability, which was classified as critical, has been found in PHP League Commonmark up to 2.8.3. This affects an unknown part of the component AttributesExtension. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-71478. The attack can be initiated remotely. There is not any exploit available.