CVE-2013-4171
Apache Roller < 5.0.1 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search results in the (1) RSS and (2) Atom feed templates.
Scores
EPSS
0.0201
EPSS Percentile
83.5%
Details
CWE
CWE-79
Status
published
Products (5)
apache/roller
< 5.0.1
apache/roller
apache/roller
apache/roller
n/a/n/a
Published
Dec 07, 2013
Tracked Since
Feb 18, 2026