Vulnerabilities > Apache > Roller > 6.1.0

DATE CVE VULNERABILITY TITLE RISK
2024-07-26 CVE-2024-25090 Unspecified vulnerability in Apache Roller
Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack.
network
low complexity
apache
5.4
2023-08-06 CVE-2023-37581 Unspecified vulnerability in Apache Roller
Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack.
network
low complexity
apache
5.4