{"id":"CVE-2025-66502","title":"A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature","summary":"A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as the template name, which is later rendered into the DOM without proper sanitization. As…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","cwe":["CWE-79"],"vendor":"foxit","product":"pdf_editor_cloud","affected":["pdf_editor_cloud < 2025-12-01"],"patched":["pdf_editor_cloud 2025-12-01"],"published":"2025-12-19","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-66502","references":[{"url":"https://www.foxit.com/support/security-bulletins.html","label":"14984358-7092-470d-8f34-ade47a7658a2"}],"tags":["nvd"],"epss":0.00179,"epssPercentile":0.06721,"ingestedAt":"2026-09-30T23:29:32.507Z","slug":"CVE-2025-66502","body":"## Overview\n\nA stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as the template name, which is later rendered into the DOM without proper sanitization. As a result, the injected script executes each time the affected PDF is loaded.\n\n## Affected\n\n- `pdf_editor_cloud < 2025-12-01`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `pdf_editor_cloud 2025-12-01`","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}