CVE 6.3 MEDIUM

Stored XSS via Create New Layer Field found in Foxit PDF Editor Cloud_CVE-2026-1592

6.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

Description

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input is embedded into the HTML output, allowing arbitrary JavaScript execution when the layer is referenced.

This issue affects pdfonline.Foxit.Com: before 2026‑02‑01.

Basic Information

ID CVE-2026-1592
Source Foxit
Published Feb 3, 2026 at 07:59

Affected Product

Vendor Foxit Software Inc.
Product pdfonline.foxit.com
Version before 2026‑02‑01
Affected Versions Foxit Software Inc. pdfonline.foxit.com before 2026‑02‑01

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.