AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-66523

MEDIUM · CVSS 6.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-01-20 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. It affects Java. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-66523
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%
Java

Original NVD Description

URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. This allows attackers to inject arbitrary scripts when an authenticated user visits a crafted link. This issue affects na1.foxitesign.foxit.com: before 2026‑01‑16.

Related CVEs

Other vulnerabilities affecting the same vendor(s)