Vulnerabilities > Apache > Roller > High

DATE CVE VULNERABILITY TITLE RISK
2021-08-18 CVE-2021-33580 Resource Exhaustion vulnerability in Apache Roller
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression.
network
low complexity
apache CWE-400
7.5
2017-07-17 CVE-2015-0249 Code Injection vulnerability in Apache Roller 5.1.0/5.1.1
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).
network
low complexity
apache CWE-94
7.2