CVE-2026-86507: Apache Roller: Stored XSS in comment moderation via comment author URL
Apache Roller 6.1.5 stored XSS can run in moderator or administrator sessions via comment-author URLs.
CVE-2026-86507 is a stored XSS flaw in Apache Roller 6.1.5 comment moderation. An anonymous attacker can store a crafted comment-author URL that executes script when a weblog moderator or global administrator views the comment management page. Apache calls the issue Important, though the published CVSS 3.1 vector is 6.1 (medium) and requires user interaction. It affects sites that allow the vulnerable comment behavior; exploitation is not reported as observed.
- Stored XSS via the comment-author URL field.
- Script runs in a weblog moderator or global administrator session.
- Apache labels it Important; CVSS 3.1 is still 6.1.
- Only sites that permit the affected comment feature are impacted.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86507 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5 Description: Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator when the comment management page is viewed. This affects sites that permit...
This source does not provide full text. Read it at seclists.org.