CVE-2019-14212: Foxitsoftware Phantompdf
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling certain XFA JavaScript due to the use of, or access to, a NULL pointer without proper validation on the object.
Affected products
- Foxitsoftware Phantompdf: before 8.3.11 (fixed in 8.3.11)
Published 2019-07-21. Last modified 2026-06-17.