Apache Roller 6.1.6 fixes 18 security vulnerabilities. Apache Roller 6.1.5 is affected. Upgrade to 6.1.6 now.
Every installation should upgrade. Some vulnerabilities need no optional feature. Vulnerabilities were found in these features: - Comments & Trackbacks, LDAP comment authentication - Multiple users and weblogs - Media file uploads - The frontpage theme - XML-RPC (MetaWeblog or Blogger API), even when disabled - AtomPub with WSSE authentication - OAuth Critical: - CVE-2026-82384: Unauthenticated XML-RPC deserialization Important: - CVE-2026-82348: Cross-weblog resource tampering - CVE-2026-82376: XXE in trackback parser - CVE-2026-82380: CSRF protection bypass - CVE-2026-82381: Stored XSS in authoring UI - CVE-2026-82383: Anonymous setup tampering - CVE-2026-82385: Velocity template sandbox escape - CVE-2026-82386: XXE in OPML import - CVE-2026-86507: Stored XSS in comment moderation Moderate: - CVE-2026-82375: SSRF via trackback and enclosure - CVE-2026-82377: Missing XML-RPC weblog authorization - CVE-2026-82378: OAuth endpoint trusts request identity - CVE-2026-82379: WSSE authentication replay - CVE-2026-82382: Reflected XSS in frontpage - CVE-2026-82387: Stored XSS via media type - CVE-2026-82546: Stored XSS via trackback links - CVE-2026-91204: Stored javascript: URI in comments - CVE-2026-91206: Reflected XSS in LDAP authenticator Each advisory is in the [email protected] archive: https://lists.apache.org/[email protected] Downloads: https://roller.apache.org/downloads/downloads.html Dave Johnson, on behalf of the Apache Roller project
