This issue affects na1.foxitesign.foxit.com: before 2026‑01‑16.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.foxit.com/support/security-bulletins.html |
|
Thu, 09 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foxit
Foxit esign |
|
| CPEs | cpe:2.3:a:foxit:esign:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Foxit
Foxit esign |
Wed, 21 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Foxitsoftware
Foxitsoftware na1.foxitesign.foxit.com |
|
| Vendors & Products |
Foxitsoftware
Foxitsoftware na1.foxitesign.foxit.com |
Tue, 20 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Jan 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. This allows attackers to inject arbitrary scripts when an authenticated user visits a crafted link. This issue affects na1.foxitesign.foxit.com: before 2026‑01‑16. | |
| Title | Reflected Cross-Site Scripting (XSS) Vulnerability in na1.foxitesign.foxit.com via Unsanitized URL Parameters | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Foxit
Published:
Updated: 2026-01-20T18:08:07.692Z
Reserved: 2025-12-04T03:37:51.889Z
Link: CVE-2025-66523
Updated: 2026-01-20T18:07:48.452Z
Status : Analyzed
Published: 2026-01-20T07:15:48.490
Modified: 2026-04-09T14:48:56.060
Link: CVE-2025-66523
No data.
OpenCVE Enrichment
Updated: 2026-01-21T11:19:39Z