CVE-2026-86507
- EPSS 0.4%
- Veröffentlicht 28.09.2026 08:27:20
- Zuletzt bearbeitet 28.09.2026 14:29:44
Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator when the comment management page is...
CVE-2026-82379
- EPSS 0.37%
- Veröffentlicht 28.09.2026 07:53:00
- Zuletzt bearbeitet 29.09.2026 16:17:12
Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniquenes...
CVE-2026-82380
- EPSS 0.28%
- Veröffentlicht 28.09.2026 07:52:27
- Zuletzt bearbeitet 28.09.2026 14:29:44
Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation filters accept a request that does not submit the ...
CVE-2026-82381
- EPSS 0.18%
- Veröffentlicht 28.09.2026 07:51:54
- Zuletzt bearbeitet 28.09.2026 14:29:44
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store crafted content that is later written into the authoring UI's JavaScript string liter...
CVE-2026-82382
- EPSS 0.25%
- Veröffentlicht 28.09.2026 07:51:31
- Zuletzt bearbeitet 28.09.2026 14:29:44
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a visitor to a weblog using the bundled frontpage theme, by supplyi...
CVE-2026-82383
- EPSS 0.49%
- Veröffentlicht 28.09.2026 07:48:34
- Zuletzt bearbeitet 28.09.2026 14:29:44
Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup actio...
CVE-2026-82384
- EPSS 0.77%
- Veröffentlicht 28.09.2026 07:47:43
- Zuletzt bearbeitet 29.09.2026 04:18:00
Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request...
CVE-2026-82375
- EPSS 0.37%
- Veröffentlicht 28.09.2026 07:46:48
- Zuletzt bearbeitet 28.09.2026 14:29:44
Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handlin...
CVE-2026-82376
- EPSS 0.3%
- Veröffentlicht 28.09.2026 07:46:10
- Zuletzt bearbeitet 29.09.2026 15:17:29
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external ...
CVE-2026-82377
- EPSS 0.54%
- Veröffentlicht 28.09.2026 07:45:40
- Zuletzt bearbeitet 29.09.2026 16:17:12
Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do...