CVE-2026-1591

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed. This issue affects pdfonline.foxit.com: before 2026‑02‑03.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:foxit:pdf_editor_cloud:*:*:*:*:*:*:*:*

History

18 Feb 2026, 16:08

Type Values Removed Values Added
References () https://www.foxit.com/support/security-bulletins.html - () https://www.foxit.com/support/security-bulletins.html - Vendor Advisory
Summary
  • (es) Foxit PDF Editor Cloud (pdfonline) contiene una vulnerabilidad de cross-site scripting almacenado en la función de carga de archivos. Un nombre de usuario malicioso se incrusta en la lista de archivos cargados sin el escape adecuado, permitiendo la ejecución arbitraria de JavaScript cuando se muestra la lista. Este problema afecta a pdfonline.foxit.com: antes del 03-02-2026.
First Time Foxit pdf Editor Cloud
Foxit
CPE cpe:2.3:a:foxit:pdf_editor_cloud:*:*:*:*:*:*:*:*

03 Feb 2026, 09:16

Type Values Removed Values Added
Summary (en) Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed. This issue affects pdfonline.Foxit.Com: before 2026‑02‑01. (en) Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed. This issue affects pdfonline.foxit.com: before 2026‑02‑03.

03 Feb 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 08:16

Updated : 2026-02-18 16:08


NVD link : CVE-2026-1591

Mitre link : CVE-2026-1591

CVE.ORG link : CVE-2026-1591


JSON object : View

Products Affected

foxit

  • pdf_editor_cloud
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')