CVE-2025-66523Patch(foxit / esign)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch foxit esign systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. This allows attackers to inject arbitrary scripts when an authenticated user visits a crafted link. This issue affects na1.foxitesign.foxit.com: before 2026‑01‑16.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • esign

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-02-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
esign

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-04: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-04: 102-0302-04
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Foxit patches multiple XSS vulnerabilities (CVE-2026-1591, CVE-2026-1592, CVE-2025-66523) in PDF Editor Cloud and eSign, fixing input validation flaws that risk arbitrary JavaScript execution. #FoxitUpdates #XSSFix #USA https://ift.tt/rbZ2pR0

    Post summary

    Foxit has released patches for several XSS CVEs, addressing input validation flaws that could allow arbitrary JavaScript execution in PDF Editor Cloud and eSign.

    00010132
    3.6K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Foxit patches XSS flaws in PDF Editor Cloud & eSign enabling arbitrary JavaScript execution Foxit fixed multiple moderate-severity XSS vulnerabilities (CVE-2026-1591 / CVE-2026-1592 in PDF Editor Cloud; CVE-2025-66523 in eSign) that let authenticated attackers inject script via attachment/layer fields or crafted URL parameters, risking session theft, data exposure, and malicious redirects. Update/ensure patched versions are deployed to eliminate this browser-context execution path. 🎯 Target: Global/Enterprise Productivity #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/foxit-pdf-editor-vulnerability/

    Post summary

    Foxit has released patches for moderate‑severity XSS vulnerabilities in PDF Editor Cloud and eSign, advising users to update their software to mitigate arbitrary JavaScript execution.

    0000049
    192 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfoxitesign---

Explore more