
🚨 CVE-2026-1591: Foxit PDF Editor Cloud Stored XSS Alert 🚨 Foxit Software A stored cross-site scripting vulnerability has been disclosed in Foxit PDF Editor Cloud, allowing attackers to inject persistent JavaScript via the file upload username field. The payload executes in the browsers of all users who later view affected file lists. A public proof of concept is available. Risk Severity: High. Public proof of concept available. Stored XSS in a cloud collaboration platform with broad user exposure. Impact: Persistent JavaScript execution in victim browsers. Session token theft and account takeover. Credential harvesting via phishing overlays. Unauthorized changes to document sharing and workflow approvals. Targeted attacks against business users with ongoing access. Root Cause: CWE-79, Improper Neutralization of Input During Web Page Generation. User supplied username metadata is stored during file upload and rendered without output encoding in shared file list views. Attackers can: Upload a file with a malicious JavaScript payload embedded in the username field. Persist the payload in upload metadata. Trigger execution when other users open shared document lists. Steal sessions, redirect users, or manipulate document permissions. Are You Affected? Vulnerable. All Foxit PDF Editor Cloud instances prior to the February 3, 2026 security patch. Fixed. Cloud service patched on 2026-02-03. Verify the admin panel shows a last update date of 2026-02-03 or later. Immediate Action Required: Verify your Foxit PDF Editor Cloud instance is fully patched. Force global session invalidation and require user reauthentication. Audit historical uploads for suspicious username values containing script or HTML payloads. Monitor logs for abnormal uploads and unexpected outbound browser requests. Stored XSS in collaboration tools turns one upload into a mass compromise. Patch and invalidate sessions immediately. 🛡️ #ostorlabCVE
Post summary
Foxit PDF Editor Cloud has a disclosed stored XSS vulnerability (CVE‑2026‑1591) with a public PoC, high severity, and a patch available as of 2026‑02‑03.






