CVE-2026-82381: Apache Roller: Stored cross-site scripting in the authoring UI
Apache Roller 6.1.5 stored XSS lets authors inject content that runs in the authoring UI.
CVE-2026-82381 is stored cross-site scripting in the Apache Roller 6.1.5 authoring UI. Apache rates it Important, while CVSS 3.1 is 5.4. A user with weblog authoring rights can store crafted content that is later written into the authoring UI's JavaScript string literals and markup sinks without neutralization. The flaw needs an authenticated author and a victim who views that UI, and no active exploitation is reported.
32