An advisory published on September 25, 2026 describes stored XSS in Apache Roller 6.1.5, rated important with a CVSS 3.1 score of 5.4 (medium).
The CVE-2026-82381 advisory says that, in Apache Roller 6.1.5, a person with author permissions on a weblog can store crafted content. Due to inadequate input neutralization, this content may be inserted into JavaScript string literals and markup insertion points in the authoring interface, where it can execute a script. The listed affected version is 6.1.5. The advisory rates the severity as important and gives a CVSS 3.1 score of 5.4, with vector AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N.
The text is an automatic translation of content from the oss-sec feed, posted by David M. Johnson on September 25, 2026. To confirm the context and check for updates, consult the original advisory in the oss-sec feed archive by searching for CVE-2026-82381; also check official CVE and Apache Roller records. The supplied advisory does not identify a fix or a corrected version. If you use AI to study or apply the material, do not submit credentials, personal data, or internal content without authorization; follow your organization’s data policy.