cbcvebase.

Apache Software Foundation Apache Roller vulnerabilities

24 known vulnerabilities affecting apache_software_foundation/apache_roller.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH9MEDIUM11

Vulnerabilities

Page 2 of 2
CVE-2026-82387P4MEDIUMCVSS 5.4v6.1.52026-09-28
CVE-2026-82387 [MEDIUM] CWE-79 CVE-2026-82387: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Rolle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file exe
nvd
CVE-2026-82382P4MEDIUMCVSS 6.1v6.1.52026-09-28
CVE-2026-82382 [MEDIUM] CWE-79 CVE-2026-82382: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Rolle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a visitor to a weblog using the bundled frontpage theme, by supplying a crafted blog-directory parameter that the directory page reflects without proper escaping. This a
nvd
CVE-2026-82381P4MEDIUMCVSS 5.4v6.1.52026-09-28
CVE-2026-82381 [MEDIUM] CWE-79 CVE-2026-82381: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Rolle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store crafted content that is later written into the authoring UI's JavaScript string literals and markup sinks without proper encoding, causing the stored script to execute in another author's
nvd
CVE-2024-46911P4MEDIUMCVSS 4.7≥ 1.0.0, < 6.1.42024-10-14
CVE-2024-46911 [MEDIUM] CWE-352 CVE-2024-46911: Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-bl Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content and this combined with a deficiency in Roller's CSRF protections allowed an escalation of privileges attack. This issue affects Apache Roller before 6.1.
nvd