CVE-2026-86507: Apache Roller: Stored XSS in comment moderation via comment author URL
Apache Roller 6.1.5 stored XSS can run in moderator or administrator sessions via comment-author URLs.
CVE-2026-86507 is a stored XSS flaw in Apache Roller 6.1.5 comment moderation. An anonymous attacker can store a crafted comment-author URL that executes script when a weblog moderator or global administrator views the comment management page. Apache calls the issue Important, though the published CVSS 3.1 vector is 6.1 (medium) and requires user interaction. It affects sites that allow the vulnerable comment behavior; exploitation is not reported as observed.
40