Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Foxitsoftware

First CVE: Apr 24, 2007Active for: 19 yearsTotal CVEs: 1,164
60.8
VTI Score
TOP TARGET

Foxitsoftware maintains a focused line of PDF manipulation and viewing applications—including PhantomPDF, Foxit Reader, and related editors—that are widely deployed across enterprise and consumer environments despite a compact product portfolio. The vendor's vulnerability profile is characterized by memory-safety weaknesses endemic to native PDF processing, with recurring issues in use-after-free conditions, out-of-bounds access, and type-confusion flaws that reflect the complexity of parsing and rendering untrusted PDF documents. PDF readers represent a high-value target due to their ubiquity and frequent exposure to unvetted external files, making this vendor's disclosures relevant to a broad defender base even when product count is limited. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
1,136
Total CVEs
More Total CVEs than 100% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Foxitsoftware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2007
19 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(24 total)

Top CVEs

Signals from CVEs in this vendor scope (1136 CVEs).

1,136 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-0837HIGH
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) ab
Mar 10, 200910.084NOYES
CVE-2018-9958HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerabil
May 17, 20188.879NOYES
CVE-2021-34833HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner
Aug 4, 20217.876NONO
CVE-2018-9948MEDIUM
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this v
May 17, 20186.575NOYES
CVE-2009-0836HIGH
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file,
Mar 10, 200910.062NOYES
CVE-2020-13557HIGH
A use after free vulnerability exists in the JavaScript engine of Foxit Software’s Foxit PDF Reader, version 10.1.0.37527. A specially crafted PDF document can trigger reuse of pre
Dec 22, 20208.860NONO
CVE-2021-34847HIGH
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulner
Aug 4, 20217.858NONO
CVE-2020-13548HIGH
In Foxit Reader 10.1.0.37527, a specially crafted PDF document can trigger reuse of previously free memory which can lead to arbitrary code execution. An attacker needs to trick th
Feb 10, 20218.857NONO
CVE-2018-20247HIGH
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFr
Dec 24, 20187.853NONO
CVE-2023-27363HIGH
Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal
May 3, 20247.850NONO
View all 1,136 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,136 CVEs
15%
77%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local551 (48.5%)
Network558 (49.1%)
Unknown27 (2.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1,093 (96.2%)
High16 (1.4%)
Unknown27 (2.4%)
User Interaction
None119 (10.5%)
Unknown27 (2.4%)
Required988 (87.0%)
Privileges Required
Low29 (2.6%)
High0 (0.0%)
None1,080 (95.1%)
Unknown27 (2.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (1136 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
0.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
1.0% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Foxitsoftware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Foxitsoftware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Foxitsoftware's Products

View all 8 CNAs →

Top CWEs