← Vulnerability feed

Vulnerability record · CVE-2007-1280 · published 10 May 2007

CVE-2007-1280: Adobe robohelp vulnerability

Adobe · Robohelp

Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a URL after a # (hash) in the URL path, as demonstrated using en/frameset-7.html, and possibly other unspecified vectors involving templates and (1) whstart.js and (2) whcsh_home.htm in WebHelp, (3) wf_startpage.js and (4) wf_startqs.htm in FlashHelp, or (5) WindowManager.dll in RoboHelp Server 6.

4.3 CVSS 2.0 Medium EPSS 5.6% · top 7.4%
4.3CVSS 2.0 base score
5.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a URL after a # (hash) in the URL path, as demonstrated using en/frameset-7.html, and possibly other unspecified vectors involving templates and (1) whstart.js and (2) whcsh_home.htm in WebHelp, (3) wf_startpage.js and (4) wf_startqs.htm in FlashHelp, or (5) WindowManager.dll in RoboHelp Server 6.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-1280 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-5327Adobe robohelp memory buffer overflow vulnerabilityMDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.EPSS 3.8%9.3CVE-2009-3068Adobe RoboHelp Server unrestricted file upload enables code executionAdobe RoboHelp Server 8 fails to restrict file uploads through the RoboHelpServer Servlet (robohelp/server). An attacker can upload a Java Archive fi…EPSS 78%analysed8.8CVE-2022-30670Adobe robohelp server improper authorization vulnerabilityRoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalatio…EPSS 1.5%8.8CVE-2021-28588Adobe robohelp server path traversal vulnerabilityAdobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authe…EPSS 6.2%7.8CVE-2021-42727Adobe robohelp server out-of-bounds write vulnerabilityAdobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in …EPSS 39%7.5CVE-2023-22274Adobe robohelp server xml external entity (xxe) vulnerabilityAdobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that c…EPSS 1.5%7.5CVE-2023-22275Adobe robohelp server sql injection vulnerabilityAdobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection…EPSS 1.3%7.5CVE-2023-22272Adobe robohelp server improper input validation vulnerabilityAdobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure …EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2007-1280), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.