CVE-2026-1592

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input is embedded into the HTML output, allowing arbitrary JavaScript execution when the layer is referenced. This issue affects pdfonline.foxit.com: before 2026‑02‑03.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:foxit:pdf_editor_cloud:*:*:*:*:*:*:*:*

History

18 Feb 2026, 16:08

Type Values Removed Values Added
Summary
  • (es) Foxit PDF Editor Cloud (pdfonline) contiene una vulnerabilidad de cross-site scripting almacenada en la función 'Crear nueva capa'. La entrada de usuario no saneada se incrusta en la salida HTML, permitiendo la ejecución arbitraria de JavaScript cuando se hace referencia a la capa. Este problema afecta a pdfonline.foxit.com: antes del 2026?02?03.
References () https://www.foxit.com/support/security-bulletins.html - () https://www.foxit.com/support/security-bulletins.html - Vendor Advisory
CPE cpe:2.3:a:foxit:pdf_editor_cloud:*:*:*:*:*:*:*:*
First Time Foxit pdf Editor Cloud
Foxit

03 Feb 2026, 09:16

Type Values Removed Values Added
Summary (en) Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input is embedded into the HTML output, allowing arbitrary JavaScript execution when the layer is referenced. This issue affects pdfonline.Foxit.Com: before 2026‑02‑01. (en) Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input is embedded into the HTML output, allowing arbitrary JavaScript execution when the layer is referenced. This issue affects pdfonline.foxit.com: before 2026‑02‑03.

03 Feb 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 08:16

Updated : 2026-02-18 16:08


NVD link : CVE-2026-1592

Mitre link : CVE-2026-1592

CVE.ORG link : CVE-2026-1592


JSON object : View

Products Affected

foxit

  • pdf_editor_cloud
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')