Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a visitor to a weblog using the bundled frontpage theme, by supplying a crafted blog-directory parameter that the directory page reflects without proper escaping. This affects only weblogs that use the bundled frontpage theme, and a victim must follow a crafted link for the script to execute. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates and contextually escapes the reflected parameter.
Published: 2026-09-28
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting
Action: Patch immediately
AI Analysis

Impact

Apache Roller version 6.1.5 contains a flaw that improperly neutralizes user input during web page generation. The bundled frontpage theme reflects the value of the blog‑directory parameter without proper escaping, allowing an attacker to embed arbitrary JavaScript in a crafted URL. If a victim follows the malicious link, the script runs in the victim’s browser, creating a reflected cross‑site scripting vulnerability identified as CWE‑79.

Affected Systems

The vulnerability affects deployments of Apache Roller 6.1.5 that use the bundled frontpage theme. No other themes or product versions are affected. Users should verify that they are running version 6.1.5 or a vulnerable earlier release and that the frontpage theme is active. Version 6.1.6 or later includes validation and contextual escaping and is not vulnerable.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a crafted URL that a victim must click; no authentication or privileged access is needed. The risk is therefore confined to users who open malicious links, making it a low‑to‑moderate threat under typical conditions.

Generated by OpenCVE AI on September 28, 2026 at 09:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Roller to version 6.1.6 or later, which validates and contextually escapes the reflected parameter.
  • If upgrading is not immediately possible, disable or replace the bundled frontpage theme until a patch is applied.
  • Implement browser‑side defenses such as a strong content‑security‑policy to mitigate the impact of any residual reflected XSS attempts.

Generated by OpenCVE AI on September 28, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache roller
Vendors & Products Apache
Apache roller

Mon, 28 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a visitor to a weblog using the bundled frontpage theme, by supplying a crafted blog-directory parameter that the directory page reflects without proper escaping. This affects only weblogs that use the bundled frontpage theme, and a victim must follow a crafted link for the script to execute. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates and contextually escapes the reflected parameter.
Title Apache Roller: Reflected cross-site scripting in the frontpage directory parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T13:31:30.477Z

Reserved: 2026-08-28T20:45:46.979Z

Link: CVE-2026-82382

cve-icon Vulnrichment

Updated: 2026-09-28T08:21:39.454Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T08:16:42.037

Modified: 2026-09-28T14:29:44.860

Link: CVE-2026-82382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T10:00:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')