Medium severity6.3NVD Advisory· Published Feb 3, 2026· Updated Jun 17, 2026
CVE-2026-1591
CVE-2026-1591
Description
Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed.
This issue affects pdfonline.foxit.com: before 2026‑02‑03.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:foxit:pdf_editor_cloud:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:foxit:pdf_editor_cloud:*:*:*:*:*:*:*:*range: <2026-02-03
- (no CPE)range: <2026-02-03
- Range: <2026-02-03
- Foxit Software Inc./pdfonline.foxit.comv5Range: before 2026‑02‑03
Patches
Vulnerability mechanics
References
1- www.foxit.com/support/security-bulletins.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.