Known Vulnerabilities for Apache Roller by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Apache Roller" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-91206 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote a... | Not Provided | 2026-09-28 | 2026-09-30 |
| CVE-2026-91204 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymo... | Not Provided | 2026-09-28 | 2026-09-30 |
| CVE-2026-86507 json | Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-82546 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthe... | Not Provided | 2026-09-28 | 2026-09-30 |
| CVE-2026-82387 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user wit... | Not Provided | 2026-09-28 | 2026-09-29 |
| CVE-2026-82386 json | Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files read... | Not Provided | 2026-09-28 | 2026-09-29 |
| CVE-2026-82385 json | Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files... | Not Provided | 2026-09-28 | 2026-09-29 |
| CVE-2026-82384 json | Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization o... | Not Provided | 2026-09-28 | 2026-09-29 |
| CVE-2026-82383 json | Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-82382 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote a... | Not Provided | 2026-09-28 | 2026-09-28 |