fonttools records
2 published records for vendor fonttools.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-91 XML Injection (aka Blind XPath Injection)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-66034Proof of concept | fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLibfonttools · fonttools · CWE-91 | Critical9.8 | — | 0.5% | Nov 28, 2025 |
30Monitor | CVE-2023-45139No exploit | fonttools XML External Entity Injection (XXE) Vulnerabilityfonttools · fonttools · CWE-611 | High7.5 | — | 1.2% | Jan 10, 2024 |
- CVE-2025-6603439Monitor
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
CriticalCVSS 9.8Proof of conceptEPSS 1%fonttools · fonttoolsNov 28, 2025
- CVE-2023-4513930Monitor
fonttools XML External Entity Injection (XXE) Vulnerability
HighCVSS 7.5No exploitEPSS 1%fonttools · fonttoolsJan 10, 2024