CVE-2026-18622Medium· 4.7▾ SunlitFoxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
pdf_editor <= 13.2.5.24109pdf_editor >= 14.0.0.33046, <= 14.0.5.33580pdf_editor >= 2023.1.0.15510, <= 2023.3.0.23028pdf_editor >= 2024.1.0.23997, <= 2024.4.1.27687pdf_editor >= 2025.1.0.27937, <= 2025.3.0.35737pdf_editor >= 2026.1.0.36452, <= 2026.1.2.36540pdf_reader <= 2026.1.2.36540pdf_editor <= 13.2.5.63482pdf_editor >= 14.0.0.68868, <= 14.0.5.69339pdf_editor >= 2023.1.0.55583, <= 2023.3.0.63083pdf_editor >= 2024.1.0.63682, <= 2024.4.1.66479pdf_editor >= 2025.1.0.66692, <= 2025.3.0.69570pdf_editor >= 2026.1.0.70169, <= 2026.1.2.70304pdf_reader <= 2026.1.2.70304Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-5936High· 8.5An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations
CVE-2024-52270High· 8.2PDF Document Spoofing in DropBox Sign(HelloSign)
CVE-2026-93386Medium· 5.4UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page
CVE-2026-78912Medium· 5.4UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page
CVE-2026-79173Medium· 5.4UI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page
CVE-2026-79180Medium· 5.4UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page