CVE-2019-14212: Foxitsoftware Phantompdf

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling certain XFA JavaScript due to the use of, or access to, a NULL pointer without proper validation on the object.

Affected products

Published 2019-07-21. Last modified 2026-06-17.