CVE-2026-82381: Apache Roller: Stored cross-site scripting in the authoring UI
Apache Roller 6.1.5 stored XSS lets authors inject content that runs in the authoring UI.
CVE-2026-82381 is stored cross-site scripting in the Apache Roller 6.1.5 authoring UI. Apache rates it Important, while CVSS 3.1 is 5.4. A user with weblog authoring rights can store crafted content that is later written into the authoring UI's JavaScript string literals and markup sinks without neutralization. The flaw needs an authenticated author and a victim who views that UI, and no active exploitation is reported.
- CVE-2026-82381 is stored XSS in the Apache Roller 6.1.5 authoring UI.
- An author can store content that lands in JavaScript literals and markup sinks.
- Vendor rates it Important; CVSS 3.1 is 5.4 and requires low privileges.
- Exploitation needs an authoring user and a victim viewing the UI.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82381 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by David M. Johnson on Sep 25 Severity: Important CVSS 3.1: 5.4 (medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected versions: - Apache Roller 6.1.5 Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store crafted content that is later written into the authoring UI's JavaScript string literals and markup sinks without...
This source does not provide full text. Read it at seclists.org.