Vulnerability index

Browse CVEs

327 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pdf Editor HIGH 7.1
CVE-2026-5941

Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to inv…

Fix: 14.0.4 / 2026.1.1+
Fix from $1,950 2026-04-27
Pdf Editor MEDIUM 5.5
CVE-2026-5937

Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" except…

Fix: 13.2.4 / 14.0.4+
Fix from $1,600 2026-04-27
Pdf Editor MEDIUM 5.5
CVE-2026-5938

Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and …

Fix: 13.2.4 / 14.0.4+
Fix from $1,600 2026-04-27
Pdf Editor MEDIUM 5.5
CVE-2026-5939

A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbi…

Fix: 14.0.4 / 2026.1.1+
Fix from $1,600 2026-04-27
Pdf Editor MEDIUM 5.5
CVE-2026-5940

Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.

Fix: 13.2.4 / 14.0.4+
Fix from $1,600 2026-04-27
Pdf Editor MEDIUM 5.5
CVE-2026-5942

Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to acce…

Fix: 13.2.4 / 14.0.4+
Fix from $1,600 2026-04-27
Pdf Services Api CRITICAL 9.8
CVE-2026-5936

An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. Thi…

Fix: 2026-04-07+
Fix from $2,300 2026-04-13
Pdf Editor HIGH 7.8
CVE-2026-3779

The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows cr…

Fix: after 2025.3.0.69570
Fix from $1,950 2026-04-01
Pdf Editor HIGH 7.8
CVE-2026-3780

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user…

Fix: after 2025.3.0.35737
Fix from $1,950 2026-04-01
Esign HIGH 7.1
CVE-2026-4947

Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, t…

Fix: 2026-03-26+
Fix from $1,950 2026-04-01
Pdf Editor HIGH 7.8
CVE-2026-3775

The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by …

Fix: after 2025.3.0.35737
Fix from $1,950 2026-04-01
Pdf Editor HIGH 7.8
CVE-2026-3777

The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and p…

Fix: after 2025.3.0.69570
Fix from $1,950 2026-04-01
Pdf Editor HIGH 7.5
CVE-2026-3774

The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content…

Fix: after 2025.3.0.35737
Fix from $1,950 2026-04-01
Pdf Editor MEDIUM 5.5
CVE-2026-3776

The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a st…

Fix: after 2025.3.0.69570
Fix from $1,600 2026-04-01
Pdf Editor MEDIUM 5.5
CVE-2026-3778

The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafte…

Fix: after 2025.3.0.69570
Fix from $1,600 2026-04-01
Pdf Editor Cloud MEDIUM 5.4
CVE-2026-1592

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input is em…

Fix: 2026-02-03+
Fix from $1,600 2026-02-03
Pdf Editor Cloud MEDIUM 5.4
CVE-2026-1591

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded …

Fix: 2026-02-03+
Fix from $1,600 2026-02-03
Esign MEDIUM 6.1
CVE-2025-66523

URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. This allows attackers to inject…

Fix: 2026-01-16+
Fix from $1,600 2026-01-20
Pdf Editor Cloud MEDIUM 5.4
CVE-2025-66520

A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonline.foxit.com). User-supplied …

Fix: 2025-12-01+
Fix from $1,600 2025-12-19
Pdf Editor Cloud MEDIUM 5.4
CVE-2025-66521

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature. A crafted payload can be inj…

Fix: 2025-12-01+
Fix from $1,600 2025-12-19
Pdf Editor Cloud MEDIUM 5.4
CVE-2025-66522

A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The ap…

Fix: after 2025-12-01
Fix from $1,600 2025-12-19
Pdf Editor Cloud MEDIUM 5.4
CVE-2025-66501

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of the Foxit eSign section. A craf…

Fix: 2025-12-01+
Fix from $1,600 2025-12-19
Pdf Editor Cloud MEDIUM 5.4
CVE-2025-66502

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as…

Fix: 2025-12-01+
Fix from $1,600 2025-12-19
Pdf Editor Cloud MEDIUM 5.4
CVE-2025-66519

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A crafted payload can be injec…

Fix: 2025-12-01+
Fix from $1,600 2025-12-19
Pdf Editor Cloud MEDIUM 5.4
CVE-2025-66500

A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and dire…

Fix: 2025-12-01+
Fix from $1,600 2025-12-19
Pdf Editor HIGH 7.8
CVE-2025-66499

A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially crafted JBIG2 data. An integer ove…

Fix: after 2025.2.1.69005
Fix from $1,950 2025-12-19
Pdf Editor HIGH 7.8
CVE-2025-66494

A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object manage…

Fix: after 2025.2.1.33197
Fix from $1,950 2025-12-19
Pdf Editor HIGH 7.8
CVE-2025-66495

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows and MacOS. When o…

Fix: after 2025.2.1.69005
Fix from $1,950 2025-12-19
Pdf Editor HIGH 7.8
CVE-2025-66496

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data.…

Fix: after 2025.2.1.33197
Fix from $1,950 2025-12-19
Pdf Editor HIGH 7.8
CVE-2025-66497

A memory corruption vulnerability exists in the 3D annotation handling of Foxit PDF Reader due to insufficient bounds checking when parsing PRC data.…

Fix: after 2025.2.1.69005
Fix from $1,950 2025-12-19