CVE-2026-91204 Details
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs.
A cross-site scripting vulnerability has been identified in Apache Roller version 6.1.5. This issue allows an anonymous remote attacker to store a comment containing a javascript: URI link. The link survives HTML comment formatting and can execute scripts in the browser of a visitor who clicks on it. This vulnerability affects only sites that have HTML enabled in comments and use the HTMLSubset comment formatter. Additionally, if comment moderation is enabled, it delays the publication of the comments. Users are advised to upgrade to Apache Roller version 6.1.6 or later, which restricts links to http, https, and mailto URIs.
Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https, and mailto URIs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/25/23 | CVE | AdvisoryMailing ListRemedy |
| https://github.com/apache/roller/pull/190 | [email protected] | Issue TrackingVendor |
| https://lists.apache.org/thread/4qzp8m0438056l5t6m6719ob79gx72lz | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache Roller | 6.1.5 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | CVE Modified | CVE |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion