Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.foxit.com/support/security-bulletins.html |
|
Tue, 23 Dec 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foxit
Foxit pdf Editor Cloud |
|
| CPEs | cpe:2.3:a:foxit:pdf_editor_cloud:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Foxit
Foxit pdf Editor Cloud |
Sun, 21 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foxitsoftware
Foxitsoftware pdfonline |
|
| Vendors & Products |
Foxitsoftware
Foxitsoftware pdfonline |
Fri, 19 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Dec 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability exists in the Digital IDs functionality of the Foxit PDF Editor Cloud (pdfonline.foxit.com). The application does not properly sanitize or encode the Common Name field of Digital IDs before inserting user-supplied content into the DOM. As a result, embedded HTML or JavaScript may execute whenever the Digital IDs dialog is accessed or when the affected PDF is loaded. | |
| Title | Foxit pdfonline.foxit.com Stored Cross-Site Scripting in Digital IDs Common Name Field | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Foxit
Published:
Updated: 2025-12-19T14:36:38.557Z
Reserved: 2025-12-04T03:37:51.889Z
Link: CVE-2025-66522
Updated: 2025-12-19T14:35:25.525Z
Status : Analyzed
Published: 2025-12-19T08:15:54.407
Modified: 2025-12-23T17:33:47.433
Link: CVE-2025-66522
No data.
OpenCVE Enrichment
Updated: 2025-12-21T21:13:10Z