CVE-2014-0030: Apache Roller
Critical severity, CVSS 9.8. EPSS: 16.9% chance of exploitation in the next 30 days.
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Affected products
- Apache Roller: version 3.1 only; version 4.0 only; version 4.0.1 only; version 5.0 only; version 5.0.1 only; version 5.0.2 only
Published 2017-10-10. Last modified 2026-06-17.