CVE-2020-12247: Foxitsoftware Phantompdf

High severity, CVSS 7.1. EPSS: 3.6% chance of exploitation in the next 30 days.

In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can obtain sensitive information from an out-of-bounds read because a text-string index continues to be used after splitting a string into two parts. A crash may also occur.

Affected products

  • Foxitsoftware Phantompdf: up to and including 9.7.2.29539; up to and including 10.0.0.35798
  • Foxitsoftware Reader: up to and including 10.0.0.35798

Published 2020-09-04. Last modified 2026-06-17.