Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store crafted content that is later written into the authoring UI's JavaScript string literals and markup sinks without proper encoding, causing the stored script to execute in another author's or administrator's browser. No optional feature or non-default configuration is required; this affects weblogs with multiple authors or administrators who are not mutually trusted. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which moves those values out of JavaScript literals and writes them as text.
Published: 2026-09-28
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Apache Roller versions prior to 6.1.6 allow a stored cross‑site scripting flaw in the authoring UI. The vulnerability arises when user‑supplied content is written directly into JavaScript string literals and markup sinks without proper neutralization. An attacker who has authoring rights can embed malicious script that will execute in the browsers of other authors or administrators, without any configuration change or optional feature. This weakness is classified as CWE‑79.

Affected Systems

The issue affects Apache Software Foundation’s Apache Roller, specifically version 6.1.5. Operators of weblogs running this version should verify the upgrade status and apply the official 6.1.6 update, which rewrites the vulnerable values as plain text rather than embedding them in JavaScript.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. No exploitation probability data is currently available via EPSS, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local to the authoring interface; the defect does not require privileged system access and no toggling of settings is necessary. Any user with authoring rights on a shared weblog can target other users, including administrators, by posting crafted content that will run in their browsers when they view the affected page.

Generated by OpenCVE AI on September 28, 2026 at 09:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Apache Roller 6.1.6 or newer, which moves vulnerable content out of JavaScript literals and writes it as text.
  • Limit authoring permissions to trusted users only, reducing the chance that malicious scripts can be inserted into shared blogs.
  • Implement manual or automated review of blog content for unexpected scripts, and monitor authoring activity for anomalous entries.

Generated by OpenCVE AI on September 28, 2026 at 09:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache roller
Vendors & Products Apache
Apache roller

Mon, 28 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store crafted content that is later written into the authoring UI's JavaScript string literals and markup sinks without proper encoding, causing the stored script to execute in another author's or administrator's browser. No optional feature or non-default configuration is required; this affects weblogs with multiple authors or administrators who are not mutually trusted. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which moves those values out of JavaScript literals and writes them as text.
Title Apache Roller: Stored cross-site scripting in the authoring UI
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T13:31:30.345Z

Reserved: 2026-08-28T20:45:12.867Z

Link: CVE-2026-82381

cve-icon Vulnrichment

Updated: 2026-09-28T08:21:36.895Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T08:16:41.913

Modified: 2026-09-28T14:29:44.860

Link: CVE-2026-82381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T10:00:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')