Security Advisory

CVE-2026-1591

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-02-03 07:57:27
Last updated 2026-02-03 18:47:39
Assigner Foxit
State PUBLISHED

Description

Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed. This issue affects pdfonline.foxit.com: before 2026‑02‑03.