CVE-2025-66500 - Foxit webplugins.foxit.com Stored Cross-Site Scripting via postMessage Vulnerabi...

CVE-2025-66500 - Foxit webplugins.foxit.com Stored Cross-Site Scripting via postMessage Vulnerabi...

CVE ID : CVE-2025-66500 Published : Dec. 19, 2025, 7:16 a.m. | 54 minutes ago Description : A stored cross-site scripting (XSS) vulnerability exists in webplugins.foxit.com. A postMessage handler fails to validate the message origin and directly assigns externalPath to a script source, allowing an attacker to execute arbitrary JavaScript when a crafted postMessage is received. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 19, 2025
Impact: XSS

Source: Telegram CVE Monitor