Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-1591

Опубликовано: 03 фев. 2026
Источник: nvd
CVSS3: 6.3
CVSS3: 5.4
EPSS Низкий

Описание

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed.

This issue affects pdfonline.foxit.com: before 2026‑02‑03.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:foxit:pdf_editor_cloud:*:*:*:*:*:*:*:*
Версия до 2026-02-03 (исключая)

EPSS

Процентиль: 9%
0.00195
Низкий

6.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.3
github
5 месяцев назад

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed. This issue affects pdfonline.foxit.com: before 2026‑02‑03.

EPSS

Процентиль: 9%
0.00195
Низкий

6.3 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79