Skip to content

Apache Roller: cross-site scripting

Medium6.1CVE-2026-82546 · Published Sep 28, 2026 · updated Sep 30, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The shipped Trackback, verification and moderation defaults allow the value to be approved and rendered as an active link; a visitor who clicks the link executes script in the weblog's origin. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which removes incoming Trackback support and suppresses non-HTTP(S) comment-author links. Users unable to upgrade should disable Trackbacks and remove untrusted Trackback comments.

Affected versions

PackageAffectedFixed in
Apache Roller
Product
<= 6.1.5No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache Karaf: command injection
High8.8Sep 28
LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and...
High7.3Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: cross-site scripting
Medium6.1Sep 28
Apache Roller: missing authentication
High8.2Sep 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.