Published on September 25, 2026, this bulletin is an automatic translation of content from the oss-sec feed. It reports CVE-2026-91204 in Apache Roller 6.1.5, classifying the issue as Cross-site Scripting (XSS), with moderate severity and a CVSS 3.1 score of 6.1.
According to the description, an anonymous remote attacker can store a comment containing a javascript: URI link. The link remains after the HTML comment is formatted and may run a script in a visitor’s browser. The score indicates that user interaction is required; the stated vector is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.
To assess exposure, check whether your installation runs version 6.1.5 and consult official Apache Roller advisories and the CVE record to confirm scope and look for remediation guidance. The supplied bulletin does not specify a fixed version; do not assume a particular update resolves the issue without confirmation from an official source.
If you use AI to summarize the notice or support an analysis, remove unnecessary names, email addresses, internal addresses, and other sensitive data. Check any conclusions against the original notice and project documentation. The item says it is an automatic translation; consult the original oss-sec feed source to verify its wording and details.