CVE-2025-55310
HIGHDescription
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. An attacker able to alter or replace the static HTML files used by the StartPage feature can cause the application to load malicious or compromised content upon startup. This may result in information disclosure, unauthorized data access, or other security impacts.
Is your site exposed to CVE-2025-55310?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| foxit | pdf_editor |
| foxit | pdf_editor |
| foxit | pdf_editor |
| foxit | pdf_editor |
| foxit | pdf_reader |
| apple | macos |
| foxit | pdf_editor |
| foxit | pdf_editor |
| foxit | pdf_editor |
| foxit | pdf_editor |
| foxit | pdf_reader |
| microsoft | windows |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-55310? +
How severe is CVE-2025-55310? +
What products are affected by CVE-2025-55310? +
How do I check if I'm vulnerable to CVE-2025-55310? +
Related Vulnerabilities
iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These …
This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at …
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in …
Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP …
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or …
A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the …