CVE-2026-82381 Details
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with authoring rights on a weblog to store crafted content that is later written into the authoring UI's JavaScript string literals and markup sinks without proper encoding, causing the stored script to execute in another author's or administrator's browser. No optional feature or non-default configuration is required; this affects weblogs with multiple authors or administrators who are not mutually trusted. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which moves those values out of JavaScript literals and writes them as text.
A stored cross-site scripting vulnerability has been identified in Apache Roller version 6.1.5. This issue allows users with authoring rights on a weblog to inject malicious content that is later executed as JavaScript in the browsers of other authors or administrators. The vulnerability arises because the injected content is not properly encoded before being displayed, enabling scripts to run unimpeded. This issue affects weblogs with multiple authors or administrators who do not fully trust each other.
Users are advised to upgrade to Apache Roller version 6.1.6 or later, which addresses this vulnerability by removing inline JavaScript event handlers from the authoring UI and replacing them with data attributes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/25/14 | CVE | AdvisoryMailing ListRemedy |
| https://github.com/apache/roller/pull/168 | [email protected] | Issue TrackingVendor |
| https://lists.apache.org/thread/5qvk6j5r8ttm4vx4ntxqt6bjz6pg4r46 | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache Roller | 6.1.5 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | CVE Modified | CVE |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion