Skip to main content

Vendor/product archive

foxit / pdf_editor_cloud CVEs

Beta · best-effort

9 CVEs tagged to foxit / pdf_editor_cloud0 Critical, 0 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2026-1592

Published Feb 3, 2026

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input is embedded into the HTML output, a…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1591

Published Feb 3, 2026

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list with…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66522

Published Dec 19, 2025

A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sa…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66521

Published Dec 19, 2025

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature. A crafted payload can be injected as the certificate name,…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66520

Published Dec 19, 2025

A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonline.foxit.com). User-supplied SVG files are not properly san…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66519

Published Dec 19, 2025

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A crafted payload can be injected into the “Create new Layer…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66502

Published Dec 19, 2025

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as the template name, which is l…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66501

Published Dec 19, 2025

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of the Foxit eSign section. A crafted payload can be stored via…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66500

Published Dec 19, 2025

A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and directly assigns externalPath to a…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1