Foxit Security Vulnerabilities (CVEs)
Track 156 security vulnerabilities affecting Foxit products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
Foxit PDF Editor Cloud (pdfonline) has a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input allows atta...
Feb 3, 2026Foxit PDF Editor Cloud (pdfonline) has a stored cross-site scripting vulnerability in its file upload feature. Malicious usernames embedded in uploade...
Feb 3, 2026A stored XSS vulnerability in Foxit PDF Editor cloud's Portfolio feature allows attackers to upload malicious SVG files containing embedded HTML/JavaS...
Dec 19, 2025A stored XSS vulnerability in Foxit PDF Online's Trusted Certificates feature allows attackers to inject malicious scripts into certificate names. Whe...
Dec 19, 2025A stored cross-site scripting vulnerability in Foxit PDF Editor Cloud allows attackers to inject malicious scripts into the Digital IDs Common Name fi...
Dec 19, 2025A stored cross-site scripting vulnerability in Foxit eSign's pdfonline.foxit.com allows attackers to inject malicious scripts via the Identity 'First ...
Dec 19, 2025A stored XSS vulnerability in Foxit PDF Online's Page Templates feature allows attackers to inject malicious scripts into template names. When users l...
Dec 19, 2025A stored XSS vulnerability in Foxit PDF Online's Layer Import functionality allows attackers to inject malicious scripts into the 'Create new Layer' f...
Dec 19, 2025A stored cross-site scripting vulnerability in webplugins.foxit.com allows attackers to inject malicious JavaScript via postMessage. This affects user...
Dec 19, 2025A heap-based buffer overflow vulnerability in Foxit PDF Reader's JBIG2 image parsing allows remote code execution when opening malicious PDF files. Th...
Dec 19, 2025A use-after-free vulnerability in Foxit PDF Reader's PDF parsing allows remote code execution when opening malicious PDF files. This affects Windows u...
Dec 19, 2025A use-after-free vulnerability in Foxit PDF Reader's annotation handling allows remote code execution when opening malicious PDF files containing craf...
Dec 19, 2025A memory corruption vulnerability in Foxit PDF Reader's 3D annotation handling allows attackers to cause out-of-bounds memory access via specially cra...
Dec 19, 2025A memory corruption vulnerability in Foxit PDF Reader allows attackers to execute arbitrary code by tricking users into opening malicious PDF files co...
Dec 19, 2025A memory corruption vulnerability in Foxit PDF Reader's 3D annotation handling allows attackers to execute arbitrary code or cause denial of service b...
Dec 19, 2025A use-after-free vulnerability in Foxit PDF software allows remote code execution when opening malicious PDF files containing crafted JavaScript. This...
Dec 19, 2025A local privilege escalation vulnerability in Foxit PDF Reader/Editor Update Service allows low-privileged local attackers to modify plugin installati...
Dec 19, 2025Foxit PDF Editor and Reader versions before 2025.2.1 contain a signature spoofing vulnerability where attackers can embed triggers (like JavaScript) i...
Dec 11, 2025This vulnerability in Foxit PDF Editor and Reader allows attackers to modify the visual content of digitally signed PDFs without invalidating the sign...
Dec 11, 2025This vulnerability in Foxit PDF software allows attackers to trigger an out-of-bounds read by tricking users into opening malicious PDF files containi...
Dec 11, 2025A use-after-free vulnerability in Foxit PDF and Editor for Windows allows memory corruption when opening a malicious PDF containing JavaScript that ca...
Dec 11, 2025A use-after-free vulnerability in Foxit PDF and Editor allows memory corruption or crashes when processing malicious PDF files containing specific Jav...
Dec 11, 2025This vulnerability allows attackers who can modify or replace static HTML files used by Foxit PDF's StartPage feature to inject malicious content that...
Dec 11, 2025This vulnerability in Foxit PDF software allows attackers to create malicious PDFs that use JavaScript to modify annotation content and clear modifica...
Dec 11, 2025A memory corruption vulnerability in Foxit PDF and Editor allows attackers to execute arbitrary code by exploiting improper state updates when deletin...
Dec 11, 2025This vulnerability in Foxit PDF software allows arbitrary code execution when processing malicious PDF files. Attackers can exploit memory corruption ...
Dec 11, 2025This vulnerability in Foxit PDF software allows memory corruption when pages are deleted via JavaScript, potentially enabling arbitrary code execution...
Dec 11, 2025This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PRC files. The flaw ...
Sep 2, 2025This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PRC files. The flaw ...
Sep 2, 2025This vulnerability in Foxit PDF Reader's Update Service allows local attackers to escalate privileges by loading a malicious library from an unsecured...
Sep 2, 2025This vulnerability in Foxit PDF Reader allows remote attackers to disclose sensitive information by tricking users into opening malicious JP2 files. T...
Sep 2, 2025Foxit PDF Reader contains an out-of-bounds read vulnerability when parsing PRC files, allowing attackers to disclose sensitive information from affect...
Sep 2, 2025This vulnerability in Foxit PDF Reader allows attackers to read memory beyond allocated bounds when parsing malicious PRC files, potentially disclosin...
Sep 2, 2025A memory corruption vulnerability in Foxit Reader allows arbitrary code execution when users open malicious PDF files containing specially crafted Jav...
Aug 13, 2025This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files containing...
Dec 30, 2024This vulnerability in Foxit PDF Reader allows local attackers to escalate privileges from low-privileged user accounts to SYSTEM level by exploiting a...
Dec 30, 2024A use-after-free vulnerability in Foxit Reader 2024.3.0.26795 allows arbitrary code execution when processing malicious PDF files containing specially...
Dec 18, 2024This CVE describes a use-after-free vulnerability in Foxit PDF Reader's annotation handling that allows information disclosure. Attackers can exploit ...
Nov 22, 2024This vulnerability in Foxit PDF Reader allows remote attackers to read memory beyond allocated buffers when processing malicious PDF files with AcroFo...
Nov 22, 2024This is a use-after-free vulnerability in Foxit PDF Reader's annotation handling that allows remote attackers to execute arbitrary code when users ope...
Nov 22, 2024This vulnerability in Foxit PDF Reader's Update Service allows local attackers to escalate privileges from a low-privileged user to SYSTEM by exploiti...
Nov 22, 2024This vulnerability in Foxit PDF Reader allows attackers to read memory beyond allocated buffers when processing malicious PDF files with specially cra...
Nov 22, 2024This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...
Nov 22, 2024This vulnerability in Foxit PDF Reader allows remote attackers to execute arbitrary code by tricking users into opening malicious PDF files. The flaw ...
Nov 22, 2024This is a use-after-free vulnerability in Foxit PDF Reader's AcroForm handling that allows remote attackers to execute arbitrary code when a user open...
Aug 21, 2024A use-after-free vulnerability in Foxit PDF Reader's Doc object handling allows remote attackers to disclose sensitive information. Attackers can expl...
Aug 21, 2024This is a use-after-free vulnerability in Foxit PDF Reader's AcroForm handling that allows remote code execution when users open malicious PDF files. ...
Aug 21, 2024CVE-2021-34976 is a use-after-free vulnerability in Foxit PDF Reader's PDF file parsing that allows remote attackers to disclose sensitive information...
May 7, 2024This vulnerability allows remote attackers to execute arbitrary code on affected Foxit PDF Reader installations by tricking users into opening malicio...
May 7, 2024CVE-2021-34973 is a use-after-free vulnerability in Foxit PDF Reader's PDF file parsing that allows attackers to disclose sensitive information. Users...
May 7, 2024Why Monitor Foxit Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 156+ known vulnerabilities affecting Foxit products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Foxit packages in under 60 seconds. No agents required - completely agentless scanning that works across Foxit deployments.
Free vulnerability database: Access detailed information about every Foxit CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Foxit CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions