CVE-2026-82382: Apache Roller: Reflected cross-site scripting in the frontpage directory parameter
Apache Roller 6.1.5 reflected XSS targets frontpage-theme visitors through a crafted directory parameter.
CVE-2026-82382 is a reflected cross-site scripting flaw in Apache Roller 6.1.5, scored CVSS 3.1 6.1 and rated Moderate. A remote attacker can supply a crafted blog-directory parameter to the bundled frontpage theme and run script in a weblog visitor's browser. The issue requires user interaction and has low confidentiality and integrity impact with changed scope. The post does not report active exploitation.
34