Apache / Roller
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-24859 | Apache Roller: Insufficient Session Expiration on Password Change | LOW | 2.1 | Apr 14, 2025 |
| CVE-2024-46911 | Apache Roller: Weakness in CSRF protection allows privilege escalation | MEDIUM | 4.7 | Oct 14, 2024 |
| CVE-2024-25090 | Apache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users mode | MEDIUM | 5.4 | Jul 26, 2024 |
| CVE-2023-37581 | Apache Roller: Roller's weblog category, weblog settings and file-upload features did not properly sanitize input could be exploited to perform Reflected Cross… | MEDIUM | 5.4 | Aug 6, 2023 |
| CVE-2021-33580 | regex injection leading to DoS | HIGH | 7.5 | Aug 18, 2021 |
| CVE-2019-0234 | A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and coul… | MEDIUM | 6.1 | Jul 15, 2019 |
| CVE-2018-17198 | Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser… | CRITICAL | 9.8 | May 28, 2019 |
| CVE-2014-0030 | The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. | CRITICAL | 9.8 | Oct 9, 2017 |
| CVE-2015-0249 | The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code… | HIGH | 7.2 | Jul 14, 2017 |
| CVE-2013-4212 | Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the firs… | MEDIUM | 6.8 | Dec 7, 2013 |
| CVE-2013-4171 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors rel… | MEDIUM | 4.3 | Dec 7, 2013 |
| CVE-2012-2381 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by le… | LOW | 3.5 | Jun 26, 2012 |
| CVE-2012-2380 | Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authe… | MEDIUM | 6.8 | Jun 26, 2012 |
| CVE-2008-6879 | Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q param… | MEDIUM | 4.3 | Jul 30, 2009 |
Showing 1 to 14 of 14 CVEs