sabberworm/php-css-parser
A Parser for CSS Files written in PHP. Allows extraction of CSS files into a data structure, manipulation of said structure and output as (optimized) CSS
Activity
- Latest release
- Jun 18, 2026
- Total releases
- 53
- Cadence
- ~15 days
- Last 12 months
- 4
Reach
- Stars
- 1.8k
Details
- License
- MIT
- First release
- Dec 12, 2012
| Version | Released | |
|---|---|---|
v9.4.0
minor
| ||
v9.3.0
minor
| ||
v9.2.0
minor
| ||
v9.1.0
minor
| ||
v9.0.0
major
| ||
v8.9.0
minor
| ||
v8.8.0
minor
| ||
v8.7.0
minor
| ||
v8.6.0
minor
| ||
v8.5.2
patch
| ||
v8.5.1
patch
| ||
8.5.0
minor
| ||
8.4.0
minor
| ||
8.3.1
patch
| ||
8.2.1
patch
| ||
8.1.1
patch
| ||
8.0.1
patch
| ||
7.0.4
patch
| ||
6.0.2
patch
| ||
5.2.1
patch
| ||
5.1.3
patch
| ||
5.0.9
patch
| ||
4.0.1
patch
| ||
3.0.1
patch
| ||
2.0.1
patch
| ||
1.0.1
patch
| ||
8.3.0
minor
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
8.2.0
minor
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
8.1.0
minor
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
8.0.0
major
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
7.0.3
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
7.0.2
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
7.0.1
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
7.0.0
major
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
6.0.1
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
6.0.0
major
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.2.0
minor
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.1.2
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.1.1
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.1.0
minor
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.0.8
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.0.7
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.0.6
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.0.5
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.0.4
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.0.3
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.0.2
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.0.1
patch
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
5.0.0
major
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev | ||
4.0.0
major
1 CVE
CVE-2020-13756
GHSA-phrq-v4q2-hmq6
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker. Affected versions
8.3.0
8.2.0
8.1.0
8.0.0
7.0.0
7.0.1
7.0.2
7.0.3
6.0.0
6.0.1
5.2.0
5.1.0
+ 15 more Show less
5.1.1
5.1.2
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
4.0.0
3.0.0
2.0.0
1.0.0
Fixed in
1.0.1
2.0.1
3.0.1
4.0.1
5.0.9
5.1.3
5.2.1
6.0.2
7.0.4
8.0.1
8.1.1
8.2.1
8.3.1
References
Updated Nov 03, 2025 · Source: OSV.dev |