CVE-2026-82382
Received Received - Intake

Reflected Cross-Site Scripting in Apache Roller

Vulnerability report for CVE-2026-82382, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Apache Software Foundation

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a visitor to a weblog using the bundled frontpage theme, by supplying a crafted blog-directory parameter that the directory page reflects without proper escaping. This affects only weblogs that use the bundled frontpage theme, and a victim must follow a crafted link for the script to execute. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which validates and contextually escapes the reflected parameter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache roller 6.1.5
apache roller 6.1.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected cross-site scripting (XSS) vulnerability in Apache Roller 6.1.5. It occurs when a remote attacker crafts a malicious link with a specially designed blog-directory parameter. When a victim visits the attacker's link, the parameter is reflected back in the web page without proper escaping, allowing the attacker to execute arbitrary JavaScript in the victim's browser. The vulnerability only affects weblogs using the bundled frontpage theme.

Detection Guidance

To detect this vulnerability, inspect Apache Roller instances running version 6.1.5 with the bundled frontpage theme enabled. Check web server logs for requests containing the 'blog-directory' parameter with unusual or crafted input. Look for reflected XSS patterns like script tags or JavaScript events in the response.

Impact Analysis

If you visit a malicious link exploiting this vulnerability, an attacker could steal your session cookies, perform actions on your behalf, or redirect you to phishing sites. This requires you to click a crafted link, so avoid suspicious links and upgrade Apache Roller to version 6.1.6 or later.

Compliance Impact

This XSS vulnerability could lead to unauthorized access to user data, violating GDPR's data protection principles and HIPAA's security requirements for protecting sensitive health information. Organizations must address this to maintain compliance with data privacy regulations.

Mitigation Strategies

Upgrade Apache Roller to version 6.1.6 or later immediately. If upgrading is not possible, disable the bundled frontpage theme or implement input validation for the 'blog-directory' parameter to accept only single ASCII letters (A-Z). Ensure proper HTML escaping is applied to all user-supplied input.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82382. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart