CVE-2025-66520: Foxit pdfonline.foxit.com Stored Cross-Site Scripting in Portfolio SVG Handling
A stored cross-site scripting (XSS) vulnerability exists in the Portfolio feature of the Foxit PDF Editor cloud (pdfonline.foxit.com). User-supplied SVG files are not properly sanitized or validated before being inserted into the HTML structure. As a result, embedded HTML or JavaScript within a crafted SVG may execute whenever the Portfolio file list is rendered.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66520?
CVE-2025-66520 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2025-66520?
To fix CVE-2025-66520, ensure that the Portfolio feature of Foxit PDF Editor is updated to the latest version that addresses this vulnerability.
What types of attacks can CVE-2025-66520 allow?
CVE-2025-66520 can allow attackers to execute malicious JavaScript in the context of the affected user’s session through stored XSS.
Which software is affected by CVE-2025-66520?
CVE-2025-66520 affects the cloud version of the Foxit PDF Editor specifically when using the Portfolio feature.
Are user-uploaded SVG files safe in Foxit PDF Editor given CVE-2025-66520?
No, user-uploaded SVG files are not safe in Foxit PDF Editor due to improper sanitization and validation, which can lead to cross-site scripting vulnerabilities.