Foxit
Foxit PDF Editor Cloud: vulnerabilidades y CVE
Foxit PDF Editor Cloud tiene 9 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses9
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-1592 | Media (5.4) | 0.20% | — | 3 feb 2026 | Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input is embedded into the HTML output, allowing arbitrary JavaScript execution… |
| CVE-2026-1591 | Media (5.4) | 0.20% | — | 3 feb 2026 | Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary… |
| CVE-2025-66522 | Media (5.4) | 0.18% | — | 19 dic 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sanitize or encode the Common Name field… |
| CVE-2025-66521 | Media (5.4) | 0.11% | — | 19 dic 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature. A crafted payload can be injected as the certificate name, which is later rendered into the DOM… |
| CVE-2025-66520 | Media (5.4) | 0.18% | — | 19 dic 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonline.foxit.com). User-supplied SVG files are not properly sanitized or validated before being… |
| CVE-2025-66501 | Media (5.4) | 0.18% | — | 19 dic 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of the Foxit eSign section. A crafted payload can be stored via the Identity “First Name” field, which… |
| CVE-2025-66500 | Media (5.4) | 0.21% | — | 19 dic 2025 | A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and directly assigns externalPath to a script source, allowing an attacker to… |
| CVE-2025-66519 | Media (5.4) | 0.18% | — | 19 dic 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A crafted payload can be injected into the “Create new Layer” field during layer import and is later… |
| CVE-2025-66502 | Media (5.4) | 0.18% | — | 19 dic 2025 | A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as the template name, which is later rendered into the DOM without… |