CVE-2026-95595

HIGH CVSS 3.1: 7.1
Updated Oct 07, 2026
Fontsplugin
Parameter Value
CVSS 7.1 (HIGH)
Affected Versions n_a — 2.0.2
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Fontsplugin
Public PoC No

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS. This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly: from n/a through 2.0.2.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Fontsplugin Disable_And_Remove_Google_Fonts_Gdpr_Dsgvo_Friendly
cpe:2.3:a:fontsplugin:disable_and_remove_google_fonts_gdpr_dsgvo_friendly:*:*:*:*:*:*:*:*
n_a <= 2.0.2