VendorsFoxitpdf_editorany version
Vulnerabilities

Foxit PDF Editor any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

298CVEs
CVE-2026-13129
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57238
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57246
Foxit PDF Editor/Reader Signature Buffer Overflow Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-57242
Foxit PDF Editor/Reader Page Use-After-Free Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-5943
Foxit PDF Editor/Reader AcroForm Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2026-04-27 · Analyzed
7.8EPSS 0.002
CVE-2026-57245
Foxit PDF Editor/Reader Signature Hyperlink Use-After-Free Vulnerability
Published 2026-07-08 · Analyzed
7.8EPSS 0.002
CVE-2026-5940
Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2026-04-27 · Analyzed
7.8EPSS 0.002
CVE-2026-5941
Foxit PDF Editor/Reader AcroForm Signature Remote Code Execution Vulnerability
Published 2026-04-27 · Analyzed
7.8EPSS 0.002
CVE-2024-32488
In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak permissions on the update-service folder allow attackers to place crafted DLL files there.
Published 2024-04-15 · Analyzed
7.8EPSS 0.002
CVE-2023-33240
Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x versions, and 10.1.11.37866 and earlier) on Windows allows Local Privilege Escalation when installed to a non-default directory because unprivileged users have access to an executable file of a system service. This is fixed in 12.1.2.
Published 2023-05-19 · Modified
7.8EPSS 0.002
CVE-2025-55312
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memory corruption, application crashes, and potentially allow an attacker to execute arbitrary code.
Published 2025-12-11 · Analyzed
7.8EPSS 0.002
CVE-2022-30557
Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution.
Published 2022-05-11 · Modified
7.5EPSS 0.044
CVE-2022-27944
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference.
Published 2022-08-06 · Modified
7.5EPSS 0.011
CVE-2022-26979
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.
Published 2022-08-06 · Modified
7.5EPSS 0.011
CVE-2025-59802
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF triggers to dynamically change the visibility of OCG content after signing (Post-Sign), allowing the visual content of a signed PDF to be modified without invalidating the signature. This may result in a mismatch between the signed content and what the signer or verifier sees, undermining the trustworthiness of the digital signature. The fixed versions are 2025.2.1, 14.0.1, and 13.2.1.
Published 2025-12-11 · Analyzed
7.5EPSS 0.003
CVE-2026-3774
Self-Modifications Affecting Altered Printing and Redaction in Foxit PDF Editor
Published 2026-04-01 · Analyzed
7.5EPSS 0.002
CVE-2024-12753
Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability
Published 2024-12-30 · Analyzed
7.3EPSS 0.003
CVE-2025-55310
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. An attacker able to alter or replace the static HTML files used by the StartPage feature can cause the application to load malicious or compromised content upon startup. This may result in information disclosure, unauthorized data access, or other security impacts.
Published 2025-12-11 · Analyzed
7.3EPSS 0.001
CVE-2024-30335
Foxit PDF Reader AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-04-02 · Analyzed
7.1EPSS 0.007
CVE-2023-42090
Foxit PDF Reader XFA Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-05-03 · Modified
7.1EPSS 0.005
CVE-2024-9246
Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
7.1EPSS 0.005
CVE-2024-9253
Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
7.1EPSS 0.004
CVE-2024-9256
Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2024-11-22 · Analyzed
7.1EPSS 0.004
CVE-2025-55308
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. A crafted PDF containing JavaScript that calls closeDoc() while internal objects are still in use can cause premature release of these objects. This use-after-free vulnerability may lead to memory corruption, potentially resulting in information disclosure when the PDF is opened.
Published 2025-12-11 · Analyzed
6.7EPSS 0.001
CVE-2025-55309
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can contain JavaScript that attaches an OnBlur action on a form field that destroys an annotation. During user right-click interaction, the program's internal focus change handling prematurely releases the annotation object, resulting in a use-after-free vulnerability that may cause memory corruption or application crashes.
Published 2025-12-11 · Analyzed
6.7EPSS 0.001
CVE-2022-24368
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16115.
Published 2022-02-18 · Modified
6.5EPSS 0.021
CVE-2022-24370
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader Foxit reader 11.0.1.0719 macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA forms. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-14819.
Published 2022-02-18 · Modified
6.5EPSS 0.019
CVE-2022-47881
Foxit PDF Reader and PDF Editor 11.2.1.53537 and earlier has an Out-of-Bounds Read vulnerability.
Published 2023-01-18 · Modified
6.5EPSS 0.007
CVE-2026-57259
Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read
Published 2026-07-08 · Analyzed
6.5EPSS 0.004
CVE-2025-55311
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.
Published 2025-12-11 · Modified
6.5EPSS 0.002
CVE-2026-3778
Stack exhaustion caused by cyclic references in Foxit PDF Editor/Reader
Published 2026-04-01 · Analyzed
6.2EPSS 0.001
CVE-2022-28681
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the deletePages method. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16825.
Published 2022-07-18 · Modified
6.1EPSS 0.009
CVE-2026-57258
Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2026-57257
Security vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap OOB Read
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2026-57255
Security vulnerability in Foxit PDF Editor/Reader — OOB Read via NaN-Bypass Clamp
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2026-57253
Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2026-57243
Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2026-57241
Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability
Published 2026-07-08 · Analyzed
6.1EPSS 0.002
CVE-2022-27359
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a this.maildoc NULL pointer dereference.
Published 2022-05-05 · Modified
5.5EPSS 0.011
CVE-2022-43640
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. Crafted data in a PDF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18629.
Published 2023-03-29 · Modified
5.5EPSS 0.009
← Prev6 / 8Next →