VYPR
Medium severity6.3NVD Advisory· Published Feb 3, 2026· Updated Jun 17, 2026

CVE-2026-1591

CVE-2026-1591

Description

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed.

This issue affects pdfonline.foxit.com: before 2026‑02‑03.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Foxit Software Inc./pdfonline.foxit.comv5
    Range: before 2026‑02‑03
  • Range: <2026-02-03
  • Foxitsoftware/PDF Editor Cloudllm-create2 versions
    <2026-02-03+ 1 more
    • (no CPE)range: <2026-02-03
    • cpe:2.3:a:foxit:pdf_editor_cloud:*:*:*:*:*:*:*:*range: <2026-02-03

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.