Vulnerabilities > Fontsplugin > Fonts > 3.2.6

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-43302 Missing Authorization vulnerability in Fontsplugin Fonts
Missing Authorization vulnerability in Fonts Plugin Fonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fonts: from n/a through 3.7.7.
network
low complexity
fontsplugin CWE-862
8.8
2024-08-26 CVE-2024-43301 Cross-Site Request Forgery (CSRF) vulnerability in Fontsplugin Fonts
Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.
network
low complexity
fontsplugin CWE-352
5.4