Foxit PDF and Editor Arbitrary HTML Injection Vulnerability

Vulnerability

A vulnerability allowing arbitrary HTML injection has been identified in Foxit PDF Reader and Foxit PDF Editor for both Windows and macOS. This issue affects several different versions and stems from the application's StartPage feature, which loads static HTML files from a user-writable location without proper validation. An attacker who can modify these HTML files could inject malicious content that the application would execute upon startup, potentially leading to information disclosure or unauthorized data access.

Impact

Exploitation of this vulnerability could result in arbitrary HTML injection, allowing attackers to execute malicious HTML or JavaScript in the context of the application.

Remediation

Users can update to the latest versions of Foxit PDF Reader or Foxit PDF Editor. For Windows, the updated versions are Foxit PDF Reader 2025.2.1 and Foxit PDF Editor 2025.2.1/14.0.1/13.2.1. For Mac, users can update to Foxit PDF Reader for Mac 2025.2.1 or Foxit PDF Editor for Mac 2025.2.1/14.0.1/13.2.1.

Added: Dec 11, 2025, 4:26 PM
Updated: Dec 11, 2025, 8:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
3.3
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.