- EPSS 0.42%
- Veröffentlicht 28.09.2026 07:45:10
- Zuletzt bearbeitet 29.09.2026 16:17:12
Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user acco...
CVE-2026-82385
- EPSS 0.28%
- Veröffentlicht 28.09.2026 07:44:07
- Zuletzt bearbeitet 29.09.2026 15:17:29
Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that...
CVE-2026-82386
- EPSS 0.29%
- Veröffentlicht 28.09.2026 07:43:31
- Zuletzt bearbeitet 29.09.2026 15:17:29
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark im...
CVE-2026-82348
- EPSS 0.37%
- Veröffentlicht 28.09.2026 07:36:45
- Zuletzt bearbeitet 29.09.2026 15:17:29
Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This ...
CVE-2026-82387
- EPSS 0.18%
- Veröffentlicht 28.09.2026 07:36:12
- Zuletzt bearbeitet 29.09.2026 15:17:29
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on Roller's origin, because the media upload feature trusts the upload-supplied...
CVE-2026-82546
- EPSS 0.28%
- Veröffentlicht 28.09.2026 07:35:38
- Zuletzt bearbeitet 30.09.2026 12:17:13
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL through the incoming Trackback endpoint when a published entry...
CVE-2026-91204
- EPSS 0.4%
- Veröffentlicht 28.09.2026 07:34:33
- Zuletzt bearbeitet 30.09.2026 12:17:14
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute...
CVE-2026-91206
- EPSS 0.4%
- Veröffentlicht 28.09.2026 07:33:13
- Zuletzt bearbeitet 30.09.2026 12:17:14
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request param...
CVE-2025-24859
- EPSS 1.08%
- Veröffentlicht 14.04.2025 08:18:54
- Zuletzt bearbeitet 03.06.2025 21:32:18
A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, e...
CVE-2024-46911
- EPSS 0.45%
- Veröffentlicht 14.10.2024 09:15:04
- Zuletzt bearbeitet 27.05.2025 19:37:34
Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitrary weblog content and this combined with a deficiency in Roller's CSRF...