https://seclists.org/oss-sec/2026/q3/953: CVE-2026-82546: Apache Roller: Stod cross-site scripting through incoming Trackback links
Affected Software
Frequently Asked Questions
Which deployments are exposed to this issue?
Apache Roller 6.1.5 is affected where a published weblog entry accepts comments and Trackbacks. The supplied Trackback, verification, and moderation defaults can allow a malicious Trackback author URL to be approved and displayed.
What does an attacker need to exploit it?
An attacker does not need authentication and can submit a crafted comment-author URL through the incoming Trackback endpoint. Exploitation requires a visitor to click the rendered malicious link.
Are default settings affected?
Yes. The shipped Trackback, verification, and moderation defaults permit the attacker-controlled value to be approved and rendered as an active link.
What should be done if upgrading is not immediately possible?
Disable Trackbacks and remove untrusted Trackback comments. Upgrading to Apache Roller 6.1.6 or later removes incoming Trackback support and suppresses non-HTTP(S) comment-author links.