CVE-2024-25090
- EPSS 0.75%
- Veröffentlicht 26.07.2024 09:15:09
- Zuletzt bearbeitet 14.03.2025 17:15:42
Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if ...
CVE-2023-37581
- EPSS 1.17%
- Veröffentlicht 06.08.2023 08:15:09
- Zuletzt bearbeitet 21.11.2024 08:11:59
Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Rolle...
CVE-2021-33580
- EPSS 3.3%
- Veröffentlicht 18.08.2021 08:15:06
- Zuletzt bearbeitet 21.11.2024 06:09:08
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programm...
CVE-2019-0234
- EPSS 3.45%
- Veröffentlicht 15.07.2019 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:16:33
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vul...
CVE-2018-17198
- EPSS 4.12%
- Veröffentlicht 28.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:04
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in...
CVE-2014-0030
- EPSS 16.87%
- Veröffentlicht 10.10.2017 01:30:20
- Zuletzt bearbeitet 13.05.2026 00:24:29
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
CVE-2015-0249
- EPSS 4.59%
- Veröffentlicht 17.07.2017 13:18:03
- Zuletzt bearbeitet 13.05.2026 00:24:29
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).
CVE-2013-4212
- EPSS 81.07%
- Veröffentlicht 07.12.2013 20:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-...
CVE-2013-4171
- EPSS 2.97%
- Veröffentlicht 07.12.2013 20:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search results in the (1) RSS and (2) Atom feed templates.
CVE-2012-2381
- EPSS 2.52%
- Veröffentlicht 26.06.2012 10:23:42
- Zuletzt bearbeitet 16.06.2026 23:41:27
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.