CVE-2026-1591: Stored XSS via Attachments Feature in https://pdfonline.foxit.com/
Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A malicious username is embedded into the upload file list without proper escaping, allowing arbitrary JavaScript execution when the list is displayed.
This issue affects pdfonline.foxit.com: before 2026‑02‑03.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1591?
CVE-2026-1591 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
How can I fix CVE-2026-1591?
To fix CVE-2026-1591, upgrade to a version of Foxit PDF Editor Cloud released after February 2026 which addresses the vulnerability.
What type of vulnerability is CVE-2026-1591?
CVE-2026-1591 is a stored cross-site scripting (XSS) vulnerability affecting the file upload feature.
Which software is affected by CVE-2026-1591?
CVE-2026-1591 affects Foxit PDF Editor Cloud software versions up to exclusive February 1, 2026.
How does CVE-2026-1591 exploit occur?
CVE-2026-1591 exploits occur when a malicious username is embedded in the uploaded file list without proper escaping, allowing for arbitrary JavaScript execution.