Stored Cross-Site Scripting Vulnerability in Foxit Web Plugins
CVE-2025-66500

6.3MEDIUM

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
19 December 2025

What is CVE-2025-66500?

A stored cross-site scripting (XSS) vulnerability has been identified in Foxit Web Plugins, where a lack of validation for the message origin in the postMessage handler allows attackers to execute arbitrary JavaScript. By sending a crafted postMessage, an attacker could exploit this weakness to manipulate user interactions on affected web applications, potentially leading to further security breaches.

Affected Version(s)

webplugins.foxit.com before 2025‑12‑01

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thisis0xczar from Novee.io
.
CVE-2025-66500 : Stored Cross-Site Scripting Vulnerability in Foxit Web Plugins