Apache Roller

18 known vulnerabilities in Apache Roller, 3 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-86507 CVSS 6.1 medium Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can…
  • CVE-2026-91206 CVSS 6.1 medium Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to…
  • CVE-2026-91204 CVSS 6.1 medium Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote…
  • CVE-2026-82546 CVSS 6.1 medium Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated…
  • CVE-2026-82387 CVSS 5.4 medium Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with…
  • CVE-2026-82386 CVSS 7.7 high Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the…
  • CVE-2026-82385 CVSS 6.5 medium Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the…
  • CVE-2026-82384 CVSS 9.8 critical Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of…
  • CVE-2026-82383 CVSS 8.2 high Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a…
  • CVE-2026-82382 CVSS 6.1 medium Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to…
  • CVE-2026-82381 CVSS 5.4 medium Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring…
  • CVE-2026-82380 CVSS 8.1 high Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing…
  • CVE-2026-82379 CVSS 7.7 high Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header…
  • CVE-2026-82378 CVSS 9.0 critical Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who…
  • CVE-2026-82377 CVSS 9.9 critical Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other…
  • CVE-2026-82376 CVSS 7.7 high Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause…
  • CVE-2026-82375 CVSS 7.4 high Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause…
  • CVE-2026-82348 CVSS 7.7 high Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog…