Skip to content

Apache Roller: cross-site scripting

Medium5.4CVE-2026-82387 · Published Sep 28, 2026 · updated Sep 29, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied content type and serves the stored file back with that type. A victim who opens the uploaded file executes the stored script. Media uploads are disabled by default; only installations that enable them are affected, and the shipped type restrictions do not block active content once uploads are on. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which derives the stored type from file content and serves non-image media as a download.

Affected versions

PackageAffectedFixed in
Apache Roller
Product
<= 6.1.5No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Karaf: command injection
High8.8Sep 28
LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and...
High7.3Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: missing authentication
High8.2Sep 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.