CVE-2025-24859
- EPSS 0.06%
- Published 14.04.2025 08:18:54
- Last modified 03.06.2025 21:32:18
A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, e...
CVE-2024-46911
- EPSS 0.15%
- Published 14.10.2024 09:15:04
- Last modified 27.05.2025 19:37:34
Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content and this combined with a deficiency in Roller's CSRF...
CVE-2024-25090
- EPSS 0.32%
- Published 26.07.2024 09:15:09
- Last modified 14.03.2025 17:15:42
Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if ...
CVE-2023-37581
- EPSS 0.51%
- Published 06.08.2023 08:15:09
- Last modified 21.11.2024 08:11:59
Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Rolle...
CVE-2021-33580
- EPSS 2.44%
- Published 18.08.2021 08:15:06
- Last modified 21.11.2024 06:09:08
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programm...
CVE-2019-0234
- EPSS 0.98%
- Published 15.07.2019 22:15:12
- Last modified 21.11.2024 04:16:33
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vul...
CVE-2018-17198
- EPSS 0.47%
- Published 28.05.2019 18:29:00
- Last modified 21.11.2024 03:54:04
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in...
CVE-2014-0030
- EPSS 14.78%
- Published 10.10.2017 01:30:20
- Last modified 20.04.2025 01:37:25
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
CVE-2015-0249
- EPSS 0.39%
- Published 17.07.2017 13:18:03
- Last modified 20.04.2025 01:37:25
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).
CVE-2013-4171
- EPSS 2.01%
- Published 07.12.2013 20:55:02
- Last modified 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search results in the (1) RSS and (2) Atom feed templates.