CVE-2012-2381

Apache Roller <5.0.1 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.

Scores

EPSS 0.0015
EPSS Percentile 34.7%

Classification

CWE
CWE-79
Status published

Affected Products (32)

apache/roller < 5.0
apache/roller
apache/roller
apache/roller
apache/roller
apache/roller
apache/roller
apache/roller
apache/roller
apache/roller
apache/roller
apache/roller
apache/roller
apache/roller
apache/roller
... and 17 more

Timeline

Published Jun 26, 2012
Tracked Since Feb 18, 2026