CVE-2020-11493: Foxitsoftware Phantompdf
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.
Affected products
- Foxitsoftware Phantompdf: up to and including 9.7.2.29539; up to and including 10.0.0.35798
- Foxitsoftware Reader: up to and including 10.0.0.35798
Published 2020-09-04. Last modified 2026-06-17.