CVE-2020-11493: Foxitsoftware Phantompdf

High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.

In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information about an uninitialized object because of direct transformation from PDF Object to Stream without concern for a crafted XObject.

Affected products

  • Foxitsoftware Phantompdf: up to and including 9.7.2.29539; up to and including 10.0.0.35798
  • Foxitsoftware Reader: up to and including 10.0.0.35798

Published 2020-09-04. Last modified 2026-06-17.