Sakura's vulnerability footprint centers on its web-font products, TS WebFonts for Sakura and TS WebFonts, which present a focused but visible exposure rooted in web application security. The recurring weakness classes—cross-site request forgery and cross-site scripting—reflect the input-handling and request-validation demands of a client-facing font-delivery service; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sakura over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34169HIGH Cross-Site Request Forgery (CSRF) vulnerability in SAKURA Internet Inc. TS Webfonts for さくらのレンタルサーバ plugin <= 3.1.2 versions. | Nov 9, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-32624MEDIUM Cross-site scripting vulnerability in TS Webfonts for SAKURA 3.1.0 and earlier allows a remote unauthenticated attacker to inject an arbitrary script. | Jul 21, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-32625MEDIUM Cross-site request forgery (CSRF) vulnerability in TS Webfonts for SAKURA 3.1.2 and earlier allows a remote unauthenticated attacker to hijack the authentication of a user and to c | Jul 21, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sakura.
Media articles that mention a CVE ID that affects a product developed by Sakura — matched by CVE ID, not by vendor name.