Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Foxit Software Incorporated

First CVE: Apr 24, 2007Active for: 19 yearsTotal CVEs: 1,164
53.2
VTI Score
TOP TARGET

Foxit Software develops a narrowly scoped but globally distributed portfolio of PDF-handling tools—readers, editors, and cloud-based signing platforms—whose ubiquity in enterprise and consumer workflows creates a significant downstream footprint despite the small product count. The vendor's vulnerability surface is heavily represented in the landscape and recurs persistently through memory-safety weaknesses including use-after-free conditions, out-of-bounds reads and writes, and NULL-pointer dereferences that are endemic to PDF parsing, plus application-layer input-validation issues such as cross-site scripting in web-facing signing interfaces. Defenders should treat Foxit advisories as broadly applicable given the prevalence of the affected products in document workflows and the parser-complexity class of the recurring flaws; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
1,136
Total CVEs
More Total CVEs than 100% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Foxit Software Incorporated over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2007
19 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Self-Reporting Analysis

Of all the CVEs published by Foxit Software Incorporated as a CNA, 100.0% affect products that Foxit Software Incorporated develops as a vendor.

100.0%
Self-reported: 63 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by Foxit Software Incorporated, 17.6% are self-published by Foxit Software Incorporated as a CNA.

17.6%
82.4%
Self-published: 63 (17.6%)
Other CNAs: 295 (82.4%)

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (1136 CVEs).

1,136 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-0837HIGH
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) ab
Mar 10, 200910.084NOYES
CVE-2018-9958HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerabil
May 17, 20188.879NOYES
CVE-2021-34833HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner
Aug 4, 20217.876NONO
CVE-2018-9948MEDIUM
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this v
May 17, 20186.575NOYES
CVE-2009-0836HIGH
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file,
Mar 10, 200910.062NOYES
CVE-2020-13557HIGH
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of pre
Dec 22, 20208.860NONO
CVE-2021-34847HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner
Aug 4, 20217.858NONO
CVE-2020-13548HIGH
In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick th
Feb 10, 20218.857NONO
CVE-2018-20247HIGH
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFr
Dec 24, 20187.853NONO
CVE-2023-27363HIGH
Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal
May 3, 20247.850NONO
View all 1,136 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,136 CVEs
15%
77%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local551 (48.5%)
Network558 (49.1%)
Unknown27 (2.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1,093 (96.2%)
High16 (1.4%)
Unknown27 (2.4%)
User Interaction
None119 (10.5%)
Unknown27 (2.4%)
Required988 (87.0%)
Privileges Required
Low29 (2.6%)
High0 (0.0%)
None1,080 (95.1%)
Unknown27 (2.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (1136 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
0.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
1.0% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Foxit Software Incorporated.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Foxit Software Incorporated — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Foxit Software Incorporated's Products

View all 8 CNAs →

Top CWEs