CVE-2026-91204

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs.

  • Published Sep 28, 2026
  • CVSS 6.1 medium
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-91204 at the National Vulnerability Database