CVE WATCH / VULNERABILITY DETAIL
CVE-2026-95595
HIGHCVSS 7.1NVD feed
Published 7 October 2026 · tracked since 8 October 2026
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS.This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly:
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-76266 HIGH 7.7
- CVE-2026-1403 MEDIUM 6.5
- CVE-2026-107229 MEDIUM 4
- CVE-2026-107353 MEDIUM 6.5
- CVE-2026-107161 HIGH 7.5
- CVE-2026-107313 MEDIUM 4.2
- CVE-2026-103371
- CVE-2026-107215 HIGH 7.5
- CVE-2026-107211
- CVE-2026-95606 CRITICAL 9.8