CVE-2026-91204
Received Received - Intake

Stored XSS in Apache Roller Comments

Vulnerability report for CVE-2026-91204, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Apache Software Foundation

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
apache roller 6.1.5
apache roller 6.1.6
apache roller to 6.1.6 (exc)
apache roller From 6.1.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-site Scripting (XSS) vulnerability in Apache Roller 6.1.5 where an attacker can store a malicious comment with a javascript: URI link. The link bypasses HTML comment formatting and executes script when clicked by a visitor. It only affects sites that allow HTML in comments and use the HTMLSubset comment formatter.

Detection Guidance

Check Apache Roller configuration for enabled HTML in comments (users.comments.htmlenabled=true) and verify if the HTMLSubset comment formatter is active. Inspect comments for stored javascript: URIs or malformed anchor tags in HTML output.

Impact Analysis

An attacker could inject malicious scripts into comments, potentially stealing user sessions, redirecting to phishing sites, or performing actions on behalf of users. Visitors clicking the link may have their browsers compromised.

Compliance Impact

This vulnerability could lead to data breaches, unauthorized access, or script execution, violating GDPR (data protection) and HIPAA (health information privacy) requirements for secure data handling and user protection.

Mitigation Strategies

Upgrade Apache Roller to version 6.1.6 or later to enforce stricter validation of anchor tags and restrict href schemes to http, https, and mailto. Disable HTML in comments if not required or switch to a safer comment formatter.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91204. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart