CVE-2025-66500
19.12.2025, 08:15
A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and directly assigns externalPath to a script source, allowing an attacker to execute arbitrary JavaScript when a crafted postMessage is received.
| Vendor | Product | Version |
|---|---|---|
| foxit | pdf_editor_cloud | 𝑥 < 2025-12-01 |
𝑥
= Vulnerable software versions