Product
apache roller
14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-24859
CVE-2024-46911
CVE-2024-25090
CVE-2023-37581
CVE-2021-33580
CVE-2019-0234
CVE-2018-17198
CVE-2014-0030
CVE-2015-0249
CVE-2013-4212
CVE-2013-4171
CVE-2012-2381
CVE-2012-2380
CVE-2008-6879
>= 1.0 and < 6.1.5
A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invali
>= 1.0 and < 6.1.4
Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by de
>= 5.0.0 and < 6.1.3
Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features
< 6.1.2
Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Ap
< 6.0.2
User controlled
request.getHeader("Referer"), request.getRequestURL() and request.getQueryString() are used to build and runall versions
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property
<= 5.1.2
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versio
all versions
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspe
all versions
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog t
<= 5.0.1
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary
<= 5.0.1
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web s
<= 5.0
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbit
<= 5.0
Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote
all versions
Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web s