cbcvebase.

Foxit Pdf Editor vulnerabilities

298 known vulnerabilities affecting foxit/pdf_editor.

Total CVEs
298
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH220MEDIUM45LOW30

Vulnerabilities

Page 11 of 15
CVE-2025-55310P3HIGHCVSS 7.3≤ 13.1.7.63027≥ 2023.1.0.55583, ≤ 2023.3.0.63083+6 more2025-12-11
CVE-2025-55310 [HIGH] CWE-494 CVE-2025-55310: An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 20 An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. An attacker able to alter or replace the static HTML files used by the StartPage feature can cause the application to load malicious or compromised content upon startup. This may result in information disclosure, unauthorized data access, or other
nvd
CVE-2022-24370P3MEDIUMCVSS 6.5fixed in 11.1.0.09252022-02-18
CVE-2022-24370 [MEDIUM] CWE-125 CVE-2022-24370: This vulnerability allows remote attackers to disclose sensitive information on affected installatio This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader Foxit reader 11.0.1.0719 macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA forms. The i
nvd
CVE-2022-27944P3HIGHCVSS 7.5fixed in 12.0.12022-08-06
CVE-2022-27944 [HIGH] CWE-476 CVE-2022-27944: Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dere Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference.
nvd
CVE-2026-57260P3HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+10 more2026-07-08
CVE-2026-57260 [HIGH] CWE-787 CVE-2026-57260: The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the applic The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly resolved a portion of the abnormal object as a pointer and used it as a valid address, ultimately causing the application to crash.
nvd
CVE-2026-57246P3HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57246 [HIGH] CWE-120 CVE-2026-57246: When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature verification, but the signature plugin does not perform validation when copying the abnormal string, causing the application to crash.
nvd
CVE-2026-57256P3HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57256 [HIGH] CWE-416 CVE-2026-57256: When the application opens a PDF and executes JavaScript, it performs abnormal operations on the lis When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form objects and their internal dictionary pointers, resulting in accessing internal members of inv
nvd
CVE-2026-57242P3HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57242 [HIGH] CWE-416 CVE-2026-57242: The application opens the PDF, and JavaScript modifies the form. However, the related objects on the The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete lifecycle management and null value validation; when the page state changes, the application continuously dereferences invalid objects, eventually leading to a crash.
nvd
CVE-2026-57252P3HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57252 [HIGH] CWE-416 CVE-2026-57252: When the application opens a PDF file, during the process of JavaScript deleting pages and removing When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel to continue accessing invalid pointers, eventually leading to the application crashing.
nvd
CVE-2022-26979P4HIGHCVSS 7.5fixed in 12.0.12022-08-06
CVE-2022-26979 [HIGH] CWE-476 CVE-2022-26979: Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when th Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.
nvd
CVE-2026-57248P3HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57248 [HIGH] CWE-763 CVE-2026-57248: When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack o When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the application to crash during subsequent release.
nvd
CVE-2026-13128P3HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-13128 [HIGH] CWE-416 CVE-2026-13128: Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will co Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document view, eventually leading to the crash of the application.
nvd
CVE-2026-57237P3HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+10 more2026-07-08
CVE-2026-57237 [HIGH] CWE-416 CVE-2026-57237: When the application opens a PDF and JavaScript modifies the properties of form fields, it causes th When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application.
nvd
CVE-2026-57244P3HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+10 more2026-07-08
CVE-2026-57244 [HIGH] CWE-416 CVE-2026-57244: After JavaScript resetting the form, the synchronization process lacks re-entry protection and objec After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the traversal process. After the pointer fails, it still continues to dereference, causing the application to crash.
nvd
CVE-2026-57240P4HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57240 [HIGH] CWE-416 CVE-2026-57240: When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic st When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid pointer references and causing the application to crash.
nvd
CVE-2026-57238P4HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57238 [HIGH] CWE-416 CVE-2026-57238: After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it att After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash.
nvd
CVE-2024-9249P4HIGHCVSS 7.1≤ 11.2.10.53951≥ 12.0, ≤ 12.1.7.15526+3 more2024-11-22
CVE-2024-9249 [HIGH] CWE-125 CVE-2024-9249: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulne Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific fla
nvd
CVE-2026-57259P4MEDIUMCVSS 6.5≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57259 [MEDIUM] CWE-611 CVE-2026-57259: The input file does not need to be strictly in a structurally valid PDF format. Instead, after revie The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within t
nvd
CVE-2026-13127P4HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-13127 [HIGH] CWE-416 CVE-2026-13127: The application opens the PDF file. JavaScript then rewrites the document to modify the page structu The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, the thumbnails still use the invalid page objects, ultimately causing the application to crash.
nvd
CVE-2026-57245P4HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57245 [HIGH] CWE-416 CVE-2026-57245: When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to validate the abnormal annotation relationships and field combinations. This results in the internal objects entering an invalid state. Eventually, during the destruction phase, an invalid pointer write occurred, causing the application to
nvd
CVE-2026-57254P4HIGHCVSS 7.8≤ 13.2.4.24048≥ 14.0.0.33046, ≤ 14.0.4.33508+4 more2026-07-08
CVE-2026-57254 [HIGH] CWE-843 CVE-2026-57254: There is an abnormal annotation within the PDF that is referenced by other objects. When the applica There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF, it fails to perform proper type checking, ultimately causing the application to crash.
nvd
Foxit Pdf Editor vulnerabilities | cvebase