CVE-2024-25858: Foxit PDF Editor

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users to review parameters of commands.

Affected products

  • Foxit PDF Editor: before 2024.4 (fixed in 2024.4)
  • Foxit PDF Reader: before 2024.4 (fixed in 2024.4)

Published 2024-03-05. Last modified 2026-06-17.