Font Awesome provides icon libraries and integration components widely used in web development, with its vulnerability footprint concentrating on cross-site scripting issues arising from improper input handling in web-facing contexts. The exposure centers on the core Font Awesome library and its integration implementations, where XSS weaknesses reflect the parsing and output-encoding demands of icon-serving and templating code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fontawesome over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4478MEDIUM The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with | Jan 16, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-5233MEDIUM The Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fawesome' shortcode in versions up to, and including, 5.0 due to insufficient in | Sep 28, 2023 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fontawesome.
Media articles that mention a CVE ID that affects a product developed by Fontawesome — matched by CVE ID, not by vendor name.