CVE-2026-1591 PUBLISHED

Stored XSS via Attachments Feature in https://pdfonline.foxit.com/

Assigner: Foxit
Reserved: 29.01.2026 Published: 03.02.2026 Updated: 03.02.2026

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed.

This issue affects pdfonline.foxit.com: before 2026‑02‑03.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
CVSS Score: 6.3

Product Status

Vendor Foxit Software Inc.
Product pdfonline.foxit.com
Versions Default: unaffected
  • Version before 2026‑02‑03 is affected

Credits

  • Novee finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE

Impacts

  • Potential arbitrary JavaScript execution