CVE-2020-14425: Foxitsoftware Foxit Reader
High severity, CVSS 7.8. EPSS: 41.1% chance of exploitation in the next 30 days.
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can execute local files and bypass the security dialog.
Affected products
- Foxitsoftware Foxit Reader: from 9.7.1, before 10.0.0 (fixed in 10.0.0)
Published 2020-11-02. Last modified 2026-06-17.