PT-2026-99795 · Apache · Apache Roller

·

CVE-2026-82546

·

Published

2026-09-28

·

Updated

2026-09-30

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Roller version 6.1.5
Description Improper neutralization of input during web page generation allows an unauthenticated remote attacker to store a crafted comment-author URL through the incoming Trackback endpoint when a published entry accepts comments and Trackbacks. Due to default verification and moderation settings, the crafted value can be approved and rendered as an active link, leading to the execution of scripts in the weblog's origin when a visitor clicks the link. This is a stored cross-site scripting issue, where malicious scripts are permanently stored on the target server.
Recommendations Upgrade to Apache Roller versions 6.1.6 and later. Disable Trackbacks and remove untrusted Trackback comments.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82546

Affected Products

Apache Roller