The Flex Local Fonts Project maintains a specialized library for local font handling within the Flex framework, with observed vulnerabilities centered on a single product and characterized by web-application input-handling weaknesses, specifically cross-site scripting flaws in page-generation contexts. Treat this as a narrowly scoped vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flex Local Fonts Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24782MEDIUM The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting | Dec 13, 2021 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flex Local Fonts Project.
Media articles that mention a CVE ID that affects a product developed by Flex Local Fonts Project — matched by CVE ID, not by vendor name.