CVE-2020-13756: Sabberworm PHP Css Parser
Critical severity, CVSS 9.8. EPSS: 49.8% chance of exploitation in the next 30 days.
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.
Affected products
- Sabberworm PHP Css Parser: before 8.3.1 (fixed in 8.3.1)
Published 2020-06-03. Last modified 2026-06-17.