← Vulnerability feed

Vulnerability record · CVE-2008-2991 · published 9 July 2008

CVE-2008-2991: Adobe robohelp server cross-site scripting vulnerability

Adobe · Robohelp Server

Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Help Errors log.

6.1 CVSS 3.1 Medium EPSS 17% · top 3.1% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Help Errors log.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-2991 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-3068Adobe RoboHelp Server unrestricted file upload enables code executionAdobe RoboHelp Server 8 fails to restrict file uploads through the RoboHelpServer Servlet (robohelp/server). An attacker can upload a Java Archive fi…EPSS 78%analysed8.8CVE-2022-30670Adobe robohelp server improper authorization vulnerabilityRoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalatio…EPSS 1.5%8.8CVE-2021-28588Adobe robohelp server path traversal vulnerabilityAdobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authe…EPSS 6.2%7.8CVE-2021-42727Adobe robohelp server out-of-bounds write vulnerabilityAdobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in …EPSS 39%7.5CVE-2023-22274Adobe robohelp server xml external entity (xxe) vulnerabilityAdobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that c…EPSS 1.5%7.5CVE-2023-22275Adobe robohelp server sql injection vulnerabilityAdobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection…EPSS 1.3%7.5CVE-2023-22272Adobe robohelp server improper input validation vulnerabilityAdobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure …EPSS 1.4%7.2CVE-2023-22273Adobe robohelp server path traversal vulnerabilityAdobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2008-2991), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.