CVE-2026-82382: Apache Roller: Reflected cross-site scripting in the frontpage directory parameter
Apache Roller 6.1.5 reflected XSS targets frontpage-theme visitors through a crafted directory parameter.
CVE-2026-82382 is a reflected cross-site scripting flaw in Apache Roller 6.1.5, scored CVSS 3.1 6.1 and rated Moderate. A remote attacker can supply a crafted blog-directory parameter to the bundled frontpage theme and run script in a weblog visitor's browser. The issue requires user interaction and has low confidentiality and integrity impact with changed scope. The post does not report active exploitation.
- CVE-2026-82382 is reflected XSS in Apache Roller 6.1.5.
- A crafted blog-directory parameter targets visitors using the bundled frontpage theme.
- CVSS 3.1 is 6.1 and requires user interaction.
- No in-the-wild exploitation is described.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82382 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Moderate CVSS 3.1: 6.1 (medium) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5 Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a visitor to a weblog using the bundled frontpage theme, by supplying a crafted blog-directory parameter...
This source does not provide full text. Read it at seclists.org.