Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Roller — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in Apache Roller, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations (CWE) associated with Apache Roller, an open-source weblogging platform. It collects a comprehensive range of security vulnerabilities affecting the product, including but not limited to cross-site scripting, improper access control, and input validation errors. The data covers incidents reported from the software’s initial releases up to the present day, ensuring a historical perspective on its security posture. Here, users can track specific vendor advisories issued by the Apache Software Foundation to understand the context and severity of each flaw. Researchers and developers can explore how specific weakness classes manifest within the codebase, facilitating deeper analysis of systemic design flaws. Additionally, you can look up the complete vulnerability history for Apache Roller to identify patterns in bug discovery and patching timelines. This resource is designed for security professionals seeking to assess risk, for developers aiming to harden their deployments, and for auditors verifying compliance. By centralizing this information, the page provides a clear view of the product’s security evolution. It serves as a reference point for understanding how legacy features may introduce modern threats. Users can correlate technical details with remediation steps provided in official notices. The content is organized to support efficient retrieval of information without requiring external searches. This approach ensures that stakeholders have direct access to critical security intelligence necessary for informed decision-making regarding system maintenance and upgrade strategies.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-86507 Apache Roller: Stored XSS in comment moderation via comment author URL CWE-79 6.1 Medium 2026-09-28
CVE-2026-82379 Apache Roller: WSSE digest authentication headers can be replayed CWE-294 7.7 High 2026-09-28
CVE-2026-82380 Apache Roller: CSRF protection bypass via self-generated salt validation CWE-352 8.1 High 2026-09-28
CVE-2026-82381 Apache Roller: Stored cross-site scripting in the authoring UI CWE-79 5.4 Medium 2026-09-28
CVE-2026-82382 Apache Roller: Reflected cross-site scripting in the frontpage directory parameter CWE-79 6.1 Medium 2026-09-28
CVE-2026-82383 Apache Roller: Anonymous setup action allows frontpage configuration tampering CWE-306 8.2 High 2026-09-28
CVE-2026-82384 Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint CWE-502 9.8 Critical 2026-09-28
CVE-2026-82375 Apache Roller: Server-side request forgery via entry trackback and enclosure URLs CWE-918 7.4 High 2026-09-28
CVE-2026-82376 Apache Roller: XML external entity processing in trackback response parser CWE-611 7.7 High 2026-09-28
CVE-2026-82377 Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers CWE-862 9.9 Critical 2026-09-28
CVE-2026-82378 Apache Roller: OAuth authorization endpoint trusts request-supplied identity CWE-863 9.0 Critical 2026-09-28
CVE-2026-82385 Apache Roller: Weblog template include escapes the Velocity sandbox and reads classpath files CWE-200 6.5 Medium 2026-09-28
CVE-2026-82386 Apache Roller: XML external entity processing in OPML bookmark import CWE-611 7.7 High 2026-09-28
CVE-2026-82348 Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups CWE-639 7.7 High 2026-09-28
CVE-2026-82387 Apache Roller: Stored cross-site scripting via uploaded media content type CWE-79 5.4 Medium 2026-09-28
CVE-2026-82546 Apache Roller: Stored cross-site scripting through incoming Trackback links CWE-79 6.1 Medium 2026-09-28
CVE-2026-91204 Apache Roller: Stored javascript: URI in HTML comments CWE-79 6.1 Medium 2026-09-28
CVE-2026-91206 Apache Roller: Reflected XSS in the optional LDAP comment authenticator CWE-79 6.1 Medium 2026-09-28
CVE-2025-24859 Apache Roller: Insufficient Session Expiration on Password Change CWE-613 8.8AI High AI 2025-04-14
CVE-2024-46911 Apache Roller: Weakness in CSRF protection allows privilege escalation CWE-352 8.8AI High AI 2024-10-14
CVE-2024-25090 Apache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users mode CWE-20 5.4 - 2024-07-26
CVE-2023-37581 Apache Roller: Roller's weblog category, weblog settings and file-upload features did not properly sanitize input could be exploited to perform Reflected Cross Site Scripting (XSS) even on a Roller site configured for untrusted users. CWE-79 5.4 - 2023-08-06
CVE-2021-33580 regex injection leading to DoS CWE-400 7.5 - 2021-08-18
CVE-2019-0234 Apache Roller 跨站脚本漏洞 6.1 - 2019-07-15
CVE-2018-17198 Apache Roller 代码问题漏洞 9.8 - 2019-05-28

All 25 known CVE vulnerabilities affecting Apache Roller with full Chinese analysis, references, and POCs where available.