VYPR

Roller

by Apache

Source repositories

CVEs (32)

  • CVE-2014-0030CriOct 10, 2017
    risk 0.68cvss 9.8epss 0.17

    The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

  • CVE-2018-17198CriMay 28, 2019
    risk 0.64cvss 9.8epss 0.04

    Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens…

  • CVE-2026-82384CriSep 28, 2026
    risk 0.57cvss 9.8epss 0.01

    Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor extension types that are deserialized during request parsing, before…

  • CVE-2026-82377CriSep 28, 2026
    risk 0.57cvss 9.9epss 0.01

    Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's…

  • CVE-2026-82378CriSep 28, 2026
    risk 0.52cvss 9.0epss 0.00

    Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an…

  • CVE-2025-24859HigApr 14, 2025
    risk 0.50cvss 8.8epss 0.01

    A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, existing sessions remain…

  • CVE-2021-33580HigAug 18, 2021
    risk 0.49cvss 7.5epss 0.03

    User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to use a browser and may send a specially crafted Referer header programmatically. Since the attacker…

  • CVE-2015-0249HigJul 17, 2017
    risk 0.47cvss 7.2epss 0.05

    The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).

  • CVE-2026-82383HigSep 28, 2026
    risk 0.46cvss 8.2epss 0.00

    Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup action remains anonymously…

  • CVE-2026-82380HigSep 28, 2026
    risk 0.46cvss 8.1epss 0.00

    Cross-Site Request Forgery (CSRF) in Apache Roller 6.1.5 allows a remote attacker to cause a logged-in user to perform state-changing actions under the victim's authority, because the CSRF validation filters accept a request that does not submit the required salt token,…

  • CVE-2026-82386HigSep 28, 2026
    risk 0.43cvss 7.7epss 0.00

    Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable…

  • CVE-2026-82379HigSep 28, 2026
    risk 0.43cvss 7.7epss 0.00

    Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness.…

  • CVE-2026-82376HigSep 28, 2026
    risk 0.43cvss 7.7epss 0.00

    Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to…

  • CVE-2026-82348HigSep 28, 2026
    risk 0.43cvss 7.7epss 0.00

    Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user…

  • CVE-2026-82375HigSep 28, 2026
    risk 0.41cvss 7.4epss 0.00

    Server-Side Request Forgery (SSRF) in Apache Roller 6.1.5 allows an authenticated user with entry-editing rights on a weblog to cause outbound HTTP requests to attacker-chosen destinations through legacy outbound Trackback and entry enclosure handling. The Trackback control is…

  • CVE-2019-0234MedJul 15, 2019
    risk 0.40cvss 6.1epss 0.03

    A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vulnerability is to upgrade to…

  • CVE-2026-82385MedSep 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller configuration files containing secrets, by authoring a Velocity template that uses an include directive to…

  • CVE-2023-37581MedAug 6, 2023
    risk 0.35cvss 5.4epss 0.01

    Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Roller configured for untrusted…

  • CVE-2026-86507MedSep 28, 2026
    risk 0.33cvss 6.1epss 0.00

    Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the session of a weblog moderator or global administrator when the comment management page is viewed. This affects sites…

  • CVE-2026-91206MedSep 28, 2026
    risk 0.33cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML…

Page 1 of 2