Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.foxit.com/support/security-bulletins.html |
|
Tue, 23 Dec 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foxit
Foxit pdf Editor Cloud |
|
| CPEs | cpe:2.3:a:foxit:pdf_editor_cloud:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Foxit
Foxit pdf Editor Cloud |
Sun, 21 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foxitsoftware
Foxitsoftware webplugins |
|
| Vendors & Products |
Foxitsoftware
Foxitsoftware webplugins |
Fri, 19 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Dec 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and directly assigns externalPath to a script source, allowing an attacker to execute arbitrary JavaScript when a crafted postMessage is received. | |
| Title | Foxit webplugins.foxit.com Stored Cross-Site Scripting via postMessage Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Foxit
Published:
Updated: 2025-12-19T17:14:25.933Z
Reserved: 2025-12-03T01:33:55.298Z
Link: CVE-2025-66500
Updated: 2025-12-19T17:14:18.496Z
Status : Analyzed
Published: 2025-12-19T08:15:52.963
Modified: 2025-12-23T17:33:39.107
Link: CVE-2025-66500
No data.
OpenCVE Enrichment
Updated: 2025-12-21T21:13:21Z