CVE-2026-1592Patch(foxit / pdf_editor_cloud)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch foxit pdf_editor_cloud systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input is embedded into the HTML output, allowing arbitrary JavaScript execution when the layer is referenced. This issue affects pdfonline.foxit.com: before 2026‑02‑03.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pdf_editor_cloud

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-03); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
pdf_editor_cloud

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-02-03: 3Mentions · 2026-02-04: 2Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-02-04: 2Technical Details · 2026-02-03: 3Technical Details · 2026-02-04: 202-0302-04
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-033
Disclosure2Patch1
2026-02-042
Patch2
Full discourse5 posts
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Foxit patches multiple XSS vulnerabilities (CVE-2026-1591, CVE-2026-1592, CVE-2025-66523) in PDF Editor Cloud and eSign, fixing input validation flaws that risk arbitrary JavaScript execution. #FoxitUpdates #XSSFix #USA https://ift.tt/rbZ2pR0

    Post summary

    Foxit has released patches for three XSS vulnerabilities (CVE‑2026‑1591, CVE‑2026‑1592, CVE‑2025‑66523) affecting PDF Editor Cloud and eSign, addressing input validation flaws that could allow arbitrary JavaScript execution.

    00010132
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1592 Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature. Unsanitized user input is embedded into the HTM… https://www.cve.org/CVERecord?id=CVE-2026-1592

    Post summary

    The snippet discloses a stored XSS flaw in Foxit PDF Editor Cloud’s Create New Layer feature, noting unsanitized input, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00010249
    56.5K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Foxit PDF Editor Cloud users, update now! Critical XSS vulnerabilities (CVE-2026-1591, CVE-2026-1592) patched to prevent arbitrary JavaScript execution. https://thedailytechfeed.com/foxit-pdf-editor-patches-critical-vulnerabilities-allowing-arbitrary-javascript-execution/ #Security #Patch #Vulnerability #JavaScript #Update #Software #Threat #CVE #Cloud #Editor #Protection #Code #Exploit #Browser #Attack #Hacking #Tech #Safety #Digital #Web

    Post summary

    The post announces that Foxit PDF Editor Cloud users should update because patches for CVE‑2026‑1591 and CVE‑2026‑1592 have been released to fix critical XSS vulnerabilities that could allow arbitrary JavaScript execution.

    0000066
    238 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Foxit patches XSS flaws in PDF Editor Cloud & eSign enabling arbitrary JavaScript execution Foxit fixed multiple moderate-severity XSS vulnerabilities (CVE-2026-1591 / CVE-2026-1592 in PDF Editor Cloud; CVE-2025-66523 in eSign) that let authenticated attackers inject script via attachment/layer fields or crafted URL parameters, risking session theft, data exposure, and malicious redirects. Update/ensure patched versions are deployed to eliminate this browser-context execution path. 🎯 Target: Global/Enterprise Productivity #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/foxit-pdf-editor-vulnerability/

    Post summary

    Foxit has released patches for CVE‑2026‑1591, CVE‑2026‑1592, and CVE‑2025‑66523—moderate‑severity XSS flaws that allow authenticated attackers to inject JavaScript via attachments or URL parameters. Users are urged to update to the latest patched versions to eliminate the browser‑context execution path.

    0000049
    192 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1592 Stored XSS in Foxit PDF Editor Cloud via Unsanitized Layer Creation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1592 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces a stored XSS vulnerability in Foxit PDF Editor Cloud, detailing its technical nature but providing no evidence of exploitation or mitigation.

    0000061
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfoxitpdf_editor_cloud---

Explore more