Foxit Software Incorporated
Self-Reporting Analysis
Of all the CVEs published by Foxit Software Incorporated as a CNA, 100.0% affect products that Foxit Software Incorporated develops as a vendor.
Of all the CVEs published that affect products developed by Foxit Software Incorporated, 17.6% are self-published by Foxit Software Incorporated as a CNA.
Trends Over Time
The number and severity of CVEs published by Foxit Software Incorporated over time
Top CVEs
All CVEs published by Foxit Software Incorporated as a CNA, regardless of affected vendor or product.
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57239HIGH The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT | Jul 8, 2026 | 7.8 | 37 | NO | NO |
CVE-2026-5936CRITICAL An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to | Apr 13, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-57240HIGH When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid pointer references and cau | Jul 8, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-57238HIGH After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash. | Jul 8, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-13126HIGH The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting | Jul 8, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-57256HIGH When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this | Jul 8, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-13129HIGH When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the | Jul 8, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-13128HIGH Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leadin | Jul 8, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-13127HIGH The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails s | Jul 8, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-57260HIGH The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly resolved a portion of the abnormal object as a pointer and use | Jul 8, 2026 | 7.8 | 32 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (63 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Foxit Software Incorporated as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Foxit Software Incorporated as a CNA — matched by CVE ID, not by organization name.