Foxit
90 known vulnerabilities
Top Products
The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, th
The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underl
During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-o
When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi
The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malfo
There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,
An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an in
When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio
The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi
After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e
When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object
The application re-enters the document structure via field processing and deletes the current page, and then continues u
When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature
When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida
After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica
During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document stat
The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete
The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related
When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie
The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use
After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the
When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under
When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t
Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the
The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the
The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a
When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some d
Document structural anomalies caused inconsistencies between page element relationships and internal index states. When
Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing
Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form fiel
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, lea
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to c
Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread
Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "
An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests t
Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process
The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted searc
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted o
The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pag
The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript ch
The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resour
The application's update service, when checking for updates, loads certain system libraries from a search path that incl
The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, ann
Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature.
Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A ma
URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. Th
Frequently Asked Questions
How many CVEs affect Foxit?
Foxit has 90 CVE records in our database, including 0 critical and 57 high severity vulnerabilities.
What are the most severe Foxit vulnerabilities?
Foxit has 0 critical severity (CVSS 9.0+) and 57 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Foxit vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Foxit products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Foxit Vulnerabilities
CyberStrike scans your infrastructure for Foxit vulnerabilities and provides real-time remediation guidance.
Get Started