Cross-site Scripting Vulnerability in Apache Roller by Apache
CVE-2026-82546

6.1MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82546?

A Cross-site Scripting vulnerability exists in Apache Roller version 6.1.5 due to improper neutralization of input during web page generation. An unauthenticated remote attacker can exploit this flaw by sending a crafted comment-author URL through the Trackback endpoint when a published entry allows comments and Trackbacks. The default settings concerning Trackback verification and moderation may permit these malicious URLs to be stored and rendered as active links. This could lead to the execution of scripts in users' browsers when they click on the links. It is advisable for users to upgrade to Apache Roller version 6.1.6 or later, which addresses this issue by removing incoming Trackback support and blocking non-HTTP(S) comment-author links. For those unable to perform the upgrade, disabling Trackbacks and removing untrusted Trackback comments is a recommended precaution.

Affected Version(s)

Apache Roller 6.1.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

m4dn355
.