CVE-2026-91204: Apache Roller: Stored javascript: URI in HTML comments
Apache Roller 6.1.5 lets anonymous users store a javascript: URI that executes for comment visitors.
CVE-2026-91204 is a stored cross-site scripting issue in Apache Roller 6.1.5. An anonymous remote attacker can post a comment containing a javascript: URI that survives HTML comment formatting and can execute script in a visitor's browser. Apache scores it CVSS 3.1 6.1 (medium), with network access, no privileges, and required user interaction. The advisory does not report active exploitation.
36