Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 2 min 120 bronnen 2 kritiek 19 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2025-66502

MEDIUM · 6.3 CVSS Gepubliceerd: CWE-79

Beschrijving

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as the template name, which is later rendered into the DOM without proper sanitization. As a result, the injected script executes each time the affected PDF is loaded.

Vendors

Foxit

Affected products

Pdf Editor Cloud

References