CVE-2026-82546: Apache Roller: Stored cross-site scripting through incoming Trackback links
Apache Roller 6.1.5 has stored XSS via crafted Trackback author URLs, CVE-2026-82546.
Apache disclosed CVE-2026-82546, a stored cross-site scripting flaw in Apache Roller 6.1.5 rated moderate with CVSS 3.1 base score 6.1. An unauthenticated remote attacker can store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The issue requires user interaction and has low confidentiality and integrity impact with changed scope. No exploitation in the wild is described.
34