CVE-2026-91204: Apache Roller: Stored javascript: URI in HTML comments
Apache Roller 6.1.5 lets anonymous users store a javascript: URI that executes for comment visitors.
CVE-2026-91204 is a stored cross-site scripting issue in Apache Roller 6.1.5. An anonymous remote attacker can post a comment containing a javascript: URI that survives HTML comment formatting and can execute script in a visitor's browser. Apache scores it CVSS 3.1 6.1 (medium), with network access, no privileges, and required user interaction. The advisory does not report active exploitation.
- Anonymous attackers can store a javascript: URI in a comment.
- The link survives HTML comment formatting and can run in a visitor's browser.
- Affects Apache Roller 6.1.5; CVSS 3.1 score 6.1.
- Rated moderate; user interaction is required.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91204 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5 Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor...
This source does not provide full text. Read it at seclists.org.