Pdf Editor Cloud
Vendor:
First CVE: Dec 19, 2025 · Active for under a year
9
Total CVEs
More Total CVEs than 86% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 11% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pdf Editor Cloud over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2025
7 months ago
Most Recent CVE
Feb 3, 2026
171 days ago
CVE Severity & Scoring
Pdf Editor Cloud9 CVEs
100%
All CVEs352,294 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required9 (100.0%)
Privileges Required
Low9 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1592MEDIUM Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input is embedded into the HTML output, al | Feb 3, 2026 | 5.4 | 22 | NO | NO |
CVE-2026-1591MEDIUM Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list witho | Feb 3, 2026 | 5.4 | 22 | NO | NO |
CVE-2025-66519MEDIUM A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A crafted payload can be injected into the “Create new Layer” | Dec 19, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-66502MEDIUM A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as the template name, which is la | Dec 19, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-66501MEDIUM A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Predefined Text feature of the Foxit eSign section. A crafted payload can be stored via t | Dec 19, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-66500MEDIUM A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and directly assigns externalPath to a | Dec 19, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-66522MEDIUM A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly san | Dec 19, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-66521MEDIUM A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Trusted Certificates feature. A crafted payload can be injected as the certificate name, | Dec 19, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-66520MEDIUM A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonline.foxit.com). User-supplied SVG files are not properly sani | Dec 19, 2025 | 5.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Pdf Editor Cloud
Top CWEs
Versions
No cataloged versions.