CVE-2016-7891 is an input validation vulnerability in Adobe RoboHelp 2015.0.3 and earlier, and RoboHelp 11 and earlier, that could lead to cross-site scripting (XSS) attacks. With a CVSS score of 6.1 (Medium), this vulnerability requires user interaction and can result in low impact to confidentiality and integrity. While not actively exploited (no KEV entry) and lacking public exploit code, it has received minimal community and media attention, with only one article mentioning it as part of a larger Adobe update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.0CPE matchmatch criteria | cpe:2.3:a:adobe:robohelp:*:*:*:*:*:*:*:* | ||
>= 2015, <= 2015.0.3CPE matchmatch criteria | cpe:2.3:a:adobe:robohelp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.