Cross-site Scripting Vulnerability in Apache Roller by Apache
CVE-2026-82546
What is CVE-2026-82546?
A Cross-site Scripting vulnerability exists in Apache Roller version 6.1.5 due to improper neutralization of input during web page generation. An unauthenticated remote attacker can exploit this flaw by sending a crafted comment-author URL through the Trackback endpoint when a published entry allows comments and Trackbacks. The default settings concerning Trackback verification and moderation may permit these malicious URLs to be stored and rendered as active links. This could lead to the execution of scripts in users' browsers when they click on the links. It is advisable for users to upgrade to Apache Roller version 6.1.6 or later, which addresses this issue by removing incoming Trackback support and blocking non-HTTP(S) comment-author links. For those unable to perform the upgrade, disabling Trackbacks and removing untrusted Trackback comments is a recommended precaution.
Affected Version(s)
Apache Roller 6.1.5