https://seclists.org/oss-sec/2026/q3/947: CVE-2026-82382: Apache Roller: flected cross-site scripting in the frontpage dictory parameter
Published Sep 25, 2026
·Updated
Affected Software
1 affected component
Apache Roller=6.1.5
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Only Apache Roller 6.1.5 weblogs using the bundled frontpage theme are affected. Weblogs using a different theme are not identified as affected by the provided advisory.
2
What must an attacker do to trigger the vulnerability?
An attacker can supply a crafted blog-directory parameter in a link to the directory page. The script executes only if a victim follows that crafted link.
3
Is authentication required to exploit it?
No. The CVSS vector indicates that the attack can be performed remotely without privileges, although it requires user interaction.
4
What should be done if the affected theme is in use?
Upgrade Apache Roller to version 6.1.6 or later. The fixed version validates and contextually escapes the reflected parameter.