CVE-2012-2381: Apache Roller
Low severity, CVSS 3.5. EPSS: 2.5% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.
Affected products
- Apache Roller: up to and including 5.0; version 0.9.5 only; version 0.9.6 only; version 0.9.6.3 only; version 0.9.6.4 only; version 0.9.7 only; …
Published 2012-06-26. Last modified 2026-06-16.