New release: Apache Roller 5.0.3 is now available on Apache mirrors world-wide and you can find it here:
http://roller.apache.org/downloads/downloads.html This release fixes a security vulnerability in Roller, listed below: CVE-2014-0030 Apache Roller XML-RPC susceptible to XML Entended Entity attacks Because of the above security vulnerability, we recommend that all sites running Apache Roller upgrade to this new release as soon as possible. Thanks, The Apache Roller team