CVE-2026-82387: Apache Roller: Stored cross-site scripting via uploaded media content type
Apache Roller 6.1.5 allows media uploaders to store XSS by spoofing content type, CVE-2026-82387.
Apache disclosed CVE-2026-82387, a stored cross-site scripting flaw in Apache Roller 6.1.5 with a CVSS 3.1 score of 5.4. A user who already has media-upload rights can store active content on the Roller origin because uploads trust the supplied content type and that content is then served. Exploitation requires low privileges and user interaction, with low confidentiality and integrity impact. No in-the-wild exploitation is reported.
28