Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Foxit

90 known vulnerabilities

30
HIGH
18
MEDIUM

Top Products

pdf editor 42 pdf reader 42 esign 2 pdf editor cloud 2 ai 1 pdf services api 1
48 CVEs
7.8
CVE-2026-57260

The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re

6.5
CVE-2026-57259

The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, th

6.1
CVE-2026-57258

The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underl

6.1
CVE-2026-57257

During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-o

7.8
CVE-2026-57256

When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi

6.1
CVE-2026-57255

The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malfo

7.8
CVE-2026-57254

There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,

6.1
CVE-2026-57253

An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an in

7.8
CVE-2026-57252

When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio

7.8
CVE-2026-57251

The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper

7.8
CVE-2026-57250

When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi

7.8
CVE-2026-57249

After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e

7.8
CVE-2026-57248

When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object

7.8
CVE-2026-57247

The application re-enters the document structure via field processing and deletes the current page, and then continues u

7.8
CVE-2026-57246

When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature

7.8
CVE-2026-57245

When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida

7.8
CVE-2026-57244

After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica

6.1
CVE-2026-57243

During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document stat

7.8
CVE-2026-57242

The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete

6.1
CVE-2026-57241

The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related

7.8
CVE-2026-57240

When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie

8.2
CVE-2026-57239

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use

7.8
CVE-2026-57238

After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the

7.8
CVE-2026-57237

When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under

7.8
CVE-2026-13129

When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t

7.8
CVE-2026-13128

Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the

7.8
CVE-2026-13127

The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the

7.8
CVE-2026-13126

The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a

8.6
CVE-2026-12057

When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some d

7.8
CVE-2026-5943

Document structural anomalies caused inconsistencies between page element relationships and internal index states. When

5.5
CVE-2026-5942

Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing

7.8
CVE-2026-5941

Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form fiel

7.8
CVE-2026-5940

Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, lea

5.5
CVE-2026-5939

A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to c

5.5
CVE-2026-5938

Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread

5.5
CVE-2026-5937

Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "

8.5
CVE-2026-5936

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests t

7.1
CVE-2026-4947

Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process

7.3
CVE-2026-3780

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted searc

7.8
CVE-2026-3779

The application's list box calculate array logic keeps stale references to page or form objects after they are deleted o

6.2
CVE-2026-3778

The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pag

5.5
CVE-2026-3777

The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript ch

5.5
CVE-2026-3776

The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resour

7.8
CVE-2026-3775

The application's update service, when checking for updates, loads certain system libraries from a search path that incl

4.7
CVE-2026-3774

The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, ann

6.3
CVE-2026-1592

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature.

6.3
CVE-2026-1591

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A ma

6.1
CVE-2025-66523

URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. Th

Frequently Asked Questions

How many CVEs affect Foxit?

Foxit has 90 CVE records in our database, including 0 critical and 57 high severity vulnerabilities.

What are the most severe Foxit vulnerabilities?

Foxit has 0 critical severity (CVSS 9.0+) and 57 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Foxit vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Foxit products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Foxit Vulnerabilities

CyberStrike scans your infrastructure for Foxit vulnerabilities and provides real-time remediation guidance.

Get Started