CVE-2025-30614
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-30614 is a Cross-site Scripting (XSS) vulnerability affecting the Haozhe Xie Google Font Fix, with versions from n/a to 2.3.1 being impacted. The issue arises due to improper neutralization of user inputs during web page generation, enabling attackers to inject malicious scripts into a victim's browser. These scripts can potentially steal user data, modify webpage content, or perform actions on behalf of the victim. This security flaw poses a significant risk, as it can be exploited through specially crafted links or webpages. Users are strongly advised to update their Haozhe Xie Google Font Fix installation to a patched version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.