Skip to content
Rota Nacional

Guides ·

CVE-2026-91204: XSS risk in Apache Roller

A bulletin describes a moderate flaw in Apache Roller 6.1.5: comments can store javascript: links that may run scripts in visitors’ browsers.

Published on September 25, 2026, this bulletin is an automatic translation of content from the oss-sec feed. It reports CVE-2026-91204 in Apache Roller 6.1.5, classifying the issue as Cross-site Scripting (XSS), with moderate severity and a CVSS 3.1 score of 6.1.

According to the description, an anonymous remote attacker can store a comment containing a javascript: URI link. The link remains after the HTML comment is formatted and may run a script in a visitor’s browser. The score indicates that user interaction is required; the stated vector is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.

To assess exposure, check whether your installation runs version 6.1.5 and consult official Apache Roller advisories and the CVE record to confirm scope and look for remediation guidance. The supplied bulletin does not specify a fixed version; do not assume a particular update resolves the issue without confirmation from an official source.

If you use AI to summarize the notice or support an analysis, remove unnecessary names, email addresses, internal addresses, and other sensitive data. Check any conclusions against the original notice and project documentation. The item says it is an automatic translation; consult the original oss-sec feed source to verify its wording and details.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free