📦 Pdf Editor Cloud

by Foxit

🔍 What is Pdf Editor Cloud?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-1592

MEDIUM CVSS 6.3 Feb 3, 2026

Foxit PDF Editor Cloud (pdfonline) has a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input allows attackers to inject malicious JavaScript that executes...

CVE-2026-1591

MEDIUM CVSS 6.3 Feb 3, 2026

Foxit PDF Editor Cloud (pdfonline) has a stored cross-site scripting vulnerability in its file upload feature. Malicious usernames embedded in uploaded files aren't properly escaped, allowing attacker...

CVE-2025-66520

MEDIUM CVSS 6.3 Dec 19, 2025

A stored XSS vulnerability in Foxit PDF Editor cloud's Portfolio feature allows attackers to upload malicious SVG files containing embedded HTML/JavaScript. When other users view the Portfolio file li...

CVE-2025-66521

MEDIUM CVSS 6.3 Dec 19, 2025

A stored XSS vulnerability in Foxit PDF Online's Trusted Certificates feature allows attackers to inject malicious scripts into certificate names. When users view the Trusted Certificates page, the sc...

CVE-2025-66522

MEDIUM CVSS 6.3 Dec 19, 2025

A stored cross-site scripting vulnerability in Foxit PDF Editor Cloud allows attackers to inject malicious scripts into the Digital IDs Common Name field. When users view affected PDFs or access the D...

CVE-2025-66501

MEDIUM CVSS 6.3 Dec 19, 2025

A stored cross-site scripting vulnerability in Foxit eSign's pdfonline.foxit.com allows attackers to inject malicious scripts via the Identity 'First Name' field. When predefined text is used or docum...

CVE-2025-66502

MEDIUM CVSS 6.3 Dec 19, 2025

A stored XSS vulnerability in Foxit PDF Online's Page Templates feature allows attackers to inject malicious scripts into template names. When users load affected PDFs, the scripts execute automatical...

CVE-2025-66519

MEDIUM CVSS 6.3 Dec 19, 2025

A stored XSS vulnerability in Foxit PDF Online's Layer Import functionality allows attackers to inject malicious scripts into the 'Create new Layer' field. When users access the Layers panel, the scri...

CVE-2025-66500

MEDIUM CVSS 6.3 Dec 19, 2025

A stored cross-site scripting vulnerability in webplugins.foxit.com allows attackers to inject malicious JavaScript via postMessage. This affects users who visit the compromised Foxit web plugin inter...