CVE-2026-82546: Apache Roller: Stored cross-site scripting through incoming Trackback links
Apache Roller 6.1.5 has stored XSS via crafted Trackback author URLs, CVE-2026-82546.
Apache disclosed CVE-2026-82546, a stored cross-site scripting flaw in Apache Roller 6.1.5 rated moderate with CVSS 3.1 base score 6.1. An unauthenticated remote attacker can store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The issue requires user interaction and has low confidentiality and integrity impact with changed scope. No exploitation in the wild is described.
- CVE-2026-82546 is rated CVSS 3.1 6.1, moderate
- Unauthenticated attacker can store XSS via Trackback author URL
- Only Apache Roller 6.1.5 is listed as affected
- Victim must accept comments and Trackbacks; user interaction required
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82546 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5 Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. The...
This source does not provide full text. Read it at seclists.org.