CVE-2018-18688: Code-Industry Master PDF Editor
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.
Affected products
- Code-Industry Master PDF Editor: version 5.1.12 only; version 5.1.68 only; version 5.1.24 only
- Foxitsoftware Foxit Reader: version 9.4 only; version 9.1.0 only; version 9.2.0 only
- Foxitsoftware Phantompdf: from 9.0, before 9.4 (fixed in 9.4); version 8.3.9 only
- Gonitro Nitro Pro: version 11.0.3.173 only
- Gonitro Nitro Reader: version 5.5.9.2 only
- Iskysoft PDF Editor 6: version 6.4.2.3521 only; version 6.6.2.3315 only; version 6.7.6.3399 only
- Iskysoft PDFELEMENT6: version 6.8.0.3523 only; version 6.8.4.3921 only; version 6.7.1.3355 only; version 6.7.6.3399 only
- Libreoffice Libreoffice: version 6.0.6.2 only; version 6.1.3.2 only; version 6.1.0.3 only
- Nuance Power PDF Standard: version 3.0.0.17 only; version 3.0.0.30 only; version 7.0 only
- Qoppa PDF Studio: version 12.0.7 only
- Qoppa PDF Studio Viewer 2018: version 2018.0.1 only; version 2018.2.0 only
- Soft-Xpansion Perfect PDF 10: version 10.0.0.1 only
- Soft-Xpansion Perfect PDF Reader: version 13.0.3 only; version 13.1.5 only
Published 2021-01-07. Last modified 2026-06-17.