Pdf Editor
Vendor:
First CVE: Aug 4, 2021 · Active for 4 years
326
Total CVEs
More Total CVEs than 100% of tracked products
54.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pdf Editor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 4, 2021
4 years ago
Most Recent CVE
Jul 8, 2026
16 days ago
CVE Severity & Scoring
Pdf Editor326 CVEs
9%
14%
75%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local283 (86.8%)
Network43 (13.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low323 (99.1%)
High3 (0.9%)
Unknown0 (0.0%)
User Interaction
None20 (6.1%)
Unknown0 (0.0%)
Required306 (93.9%)
Privileges Required
Low11 (3.4%)
High0 (0.0%)
None315 (96.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (326 CVEs).
326 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34833HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner | Aug 4, 2021 | 7.8 | 76 | NO | NO |
CVE-2021-34847HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner | Aug 4, 2021 | 7.8 | 58 | NO | NO |
CVE-2023-27363HIGH Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal | May 3, 2024 | 7.8 | 50 | NO | NO |
CVE-2021-34850HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner | Aug 4, 2021 | 7.8 | 44 | NO | NO |
CVE-2026-57239HIGH The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT | Jul 8, 2026 | 7.8 | 37 | NO | NO |
CVE-2022-24954CRITICAL Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substring | Feb 11, 2022 | 9.8 | 36 | NO | NO |
CVE-2026-57240HIGH When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid pointer references and cau | Jul 8, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-57238HIGH After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash. | Jul 8, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-13126HIGH The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting | Jul 8, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-57256HIGH When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this | Jul 8, 2026 | 7.8 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (326 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (326 CVEs).
Media Mentions
Signals from CVEs in this product scope (326 CVEs).
Top CNAs Publishing CVEs For Pdf Editor
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2025.2.0.68868 | 2 | 6.4 | 0.2% | 0 | 0 |
| 2025.2.0.33046 | 2 | 6.4 | 0.2% | 0 | 0 |
| 2025.1.0.66692 | 12 | 6.9 | 0.2% | 0 | 0 |
| 2025.1.0.27937 | 18 | 6.7 | 0.2% | 0 | 0 |
| 2024.1.0.63682 | 1 | 8.8 | 15.6% | 0 | 0 |
| 2024.1.0.23997 | 3 | 8.8 | 16.3% | 0 | 0 |
| 2023.2.0.61611 | 4 | 4.4 | 0.4% | 0 | 0 |
| 2023.2.0.21408 | 14 | 5.3 | 0.4% | 0 | 0 |
| 2023.1.0.55583 | 4 | 4.4 | 0.4% | 0 | 0 |
| 2023.1.0.15510 | 24 | 5.7 | 0.4% | 0 | 0 |
| 14.0.0.68868 | 2 | 6.4 | 0.2% | 0 | 0 |
| 14.0.0.33046 | 2 | 6.4 | 0.2% | 0 | 0 |
| 13.0.0.61829 | 4 | 4.4 | 0.4% | 0 | 0 |
| 13.0.0.21632 | 14 | 5.3 | 0.4% | 0 | 0 |
| 12.0.0.12394 | 16 | 6.8 | 0.9% | 0 | 0 |
| 11.3.1 | 1 | 9.8 | 1.8% | 0 | 0 |
| 11.0.1.49938 | 28 | 7.3 | 0.4% | 0 | 0 |
| 11.0.0.49893 | 51 | 7.5 | 5.7% | 0 | 0 |