Foxit Pdf Editor vulnerabilities
298 known vulnerabilities affecting foxit/pdf_editor.
Total CVEs
298
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH220MEDIUM45LOW30
Vulnerabilities
Page 8 of 15
CVE-2025-9330P3HIGHCVSS 7.8≤ 13.1.7.23637≥ 2023.1.0.15510, ≤ 2023.3.0.23028+2 more2025-09-02
CVE-2025-9330 [HIGH] CWE-427 CVE-2025-9330: Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerab
Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
T
nvd
CVE-2025-55312P3HIGHCVSS 7.8≤ 13.1.7.63027≥ 2023.1.0.55583, ≤ 2023.3.0.63083+5 more2025-12-11
CVE-2025-55312 [HIGH] CWE-476 CVE-2025-55312: An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When
An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume these states are valid, causing dereference of invalid or released memory. This can lead to memor
nvd
CVE-2021-45980P3HIGHCVSS 7.8fixed in 11.12022-01-04
CVE-2021-45980 [HIGH] CVE-2021-45980: Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary cod
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.
nvd
CVE-2021-45978P3HIGHCVSS 7.8fixed in 11.12022-01-04
CVE-2021-45978 [HIGH] CWE-78 CVE-2021-45978: Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary cod
Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoURL in the XFA API.
nvd
CVE-2022-24908P3HIGHCVSS 7.8fixed in 10.1.7≥ 11.0.0, < 11.2.12023-03-28
CVE-2022-24908 [HIGH] CWE-125 CVE-2022-24908: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can t
nvd
CVE-2022-24907P3HIGHCVSS 7.8fixed in 10.1.7≥ 11.0.0, < 11.2.12023-03-28
CVE-2022-24907 [HIGH] CWE-125 CVE-2022-24907: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 image can t
nvd
CVE-2022-37377P3HIGHCVSS 7.8fixed in 10.1.9≥ 11.0.0, < 11.2.3+2 more2023-03-29
CVE-2022-37377 [HIGH] CWE-843 CVE-2022-37377: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fo
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor 11.1.1.53537;. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within JavaScript optimizations. The issue results from an imprope
nvd
CVE-2024-30323P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0.49893, ≤ 11.2.8.53842+3 more2024-04-03
CVE-2024-30323 [HIGH] CWE-125 CVE-2024-30323: Foxit PDF Reader template Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability
Foxit PDF Reader template Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exis
nvd
CVE-2024-30348P3HIGHCVSS 7.8≤ 11.1.6.0109≥ 12.0.0.0601, ≤ 12.1.2.55366+7 more2024-04-02
CVE-2024-30348 [HIGH] CWE-787 CVE-2024-30348: Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vuln
Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific
nvd
CVE-2024-30341P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0, < 11.2.8.53842+3 more2024-04-02
CVE-2024-30341 [HIGH] CWE-125 CVE-2024-30341: Foxit PDF Reader Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabili
Foxit PDF Reader Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw ex
nvd
CVE-2024-30359P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0.49893, ≤ 11.2.8.53842+3 more2024-04-02
CVE-2024-30359 [HIGH] CWE-125 CVE-2024-30359: Foxit PDF Reader AcroForm 3D Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabil
Foxit PDF Reader AcroForm 3D Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw e
nvd
CVE-2024-30349P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0.49893, ≤ 11.2.8.53842+3 more2024-04-02
CVE-2024-30349 [HIGH] CWE-787 CVE-2024-30349: Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vuln
Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific
nvd
CVE-2024-9248P3HIGHCVSS 7.8≤ 11.2.10.53951≥ 12.0, ≤ 12.1.7.15526+3 more2024-11-22
CVE-2024-9248 [HIGH] CWE-787 CVE-2024-9248: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vuln
Foxit PDF Reader PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific fl
nvd
CVE-2023-38119P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.6.53790+1 more2024-05-03
CVE-2023-38119 [HIGH] CWE-125 CVE-2023-38119: Foxit PDF Reader AcroForm signature Out-Of-Bounds Read Remote Code Execution Vulnerability. This vul
Foxit PDF Reader AcroForm signature Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific
nvd
CVE-2023-38118P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.6.53790+1 more2024-05-03
CVE-2023-38118 [HIGH] CWE-787 CVE-2023-38118: Foxit PDF Reader AcroForm Doc Object Out-Of-Bounds Write Remote Code Execution Vulnerability. This v
Foxit PDF Reader AcroForm Doc Object Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specif
nvd
CVE-2023-42089P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.7.53812+2 more2024-05-03
CVE-2023-42089 [HIGH] CWE-416 CVE-2023-42089: Foxit PDF Reader templates Use-After-Free Information Disclosure Vulnerability. This vulnerability a
Foxit PDF Reader templates Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific fla
nvd
CVE-2024-9251P3HIGHCVSS 7.8≤ 11.2.10.53951≥ 12.0, ≤ 12.1.7.15526+3 more2024-11-22
CVE-2024-9251 [HIGH] CWE-416 CVE-2024-9251: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability
Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw
nvd
CVE-2024-9252P3HIGHCVSS 7.8≤ 11.2.10.53951≥ 12.0, ≤ 12.1.7.15526+3 more2024-11-22
CVE-2024-9252 [HIGH] CWE-416 CVE-2024-9252: Foxit PDF Reader AcroForm Use-After-Free Information Disclosure Vulnerability. This vulnerability al
Foxit PDF Reader AcroForm Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw e
nvd
CVE-2024-9247P3HIGHCVSS 7.8≤ 11.2.10.53951≥ 12.0, ≤ 12.1.7.15526+3 more2024-11-22
CVE-2024-9247 [HIGH] CWE-787 CVE-2024-9247: Foxit PDF Reader Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabil
Foxit PDF Reader Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exi
nvd
CVE-2023-51560P3HIGHCVSS 7.8≤ 10.1.12.37872≥ 11.0.0, ≤ 11.2.7.53812+4 more2024-05-03
CVE-2023-51560 [HIGH] CWE-843 CVE-2023-51560: Foxit PDF Reader Annotation Type Confusion Remote Code Execution Vulnerability. This vulnerability a
Foxit PDF Reader Annotation Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists
nvd