CVE-2015-0249: Apache Roller

High severity, CVSS 7.2. EPSS: 4.6% chance of exploitation in the next 30 days.

The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).

Affected products

  • Apache Roller: version 5.1.0 only; version 5.1.1 only

Published 2017-07-17. Last modified 2026-06-17.