← Vulnerability feed

Vulnerability record · CVE-2020-13756 · published 3 June 2020

CVE-2020-13756: Sabberworm PHP CSS Parser eval injection allows remote code execution

SSabberworm · Php Css Parser

Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, so attacker-supplied CSS can be executed as PHP code. The flaw is reachable when the allSelectors() or getSelectorsBySpecificity() functions are called with attacker-controlled input, making it a serious risk for any application that parses untrusted CSS.

9.8 CVSS 3.1 Critical EPSS 50% · top 1.1% CWE-94 · Code injection
9.8CVSS 3.1 base score, v2 7.5
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and public exploit references make this a critical remote code execution risk.

What it is

Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, so attacker-supplied CSS can be executed as PHP code. The flaw is reachable when the allSelectors() or getSelectorsBySpecificity() functions are called with attacker-controlled input, making it a serious risk for any application that parses untrusted CSS.

Impact

An attacker can execute arbitrary PHP code in the context of the web application, leading to full compromise of confidentiality, integrity and availability of the affected host.

Attack surface

The vulnerability is network-reachable with no authentication and no user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N). It is triggered when the application passes attacker-controlled CSS into allSelectors() or getSelectorsBySpecificity().

Exploitation

Public exploit references exist (Packet Storm and Full Disclosure entries tagged Exploit), and EPSS estimates a 30-day exploitation probability of about 0.498 (98.8th percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded.

What to do

  • Upgrade Sabberworm PHP CSS Parser to version 8.3.1 or later, which contains the patch commit 2ebf59e8bfbf6cfc1653a5f0ed743b95062c62a4.
  • If immediate upgrade is not possible, avoid calling allSelectors() or getSelectorsBySpecificity() on untrusted CSS input.
  • Sanitize or strictly validate any CSS passed into the parser, and treat all external CSS as untrusted.
  • Check for bundled or vendored copies of the library in dependencies and update those as well.

Detection

  • Search application and dependency manifests for Sabberworm PHP CSS Parser versions below 8.3.1.
  • Monitor PHP error and application logs for eval-related errors or unexpected code execution originating from CSS parsing paths.
  • Review code paths that call allSelectors() or getSelectorsBySpecificity() to confirm whether input can be attacker-controlled.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13756 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2026-34197Apache ActiveMQ Jolokia JMX bridge code injection via broker config URIApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default policy that allows exec operations on all org.apache.acti…KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2020-13756), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.