📦 Roller

by Apache

🔍 What is Roller?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-24859

HIGH CVSS 8.8 Apr 14, 2025

Apache Roller versions up to 6.1.4 have a session management vulnerability where active user sessions remain valid after password changes. This allows attackers who have compromised credentials to mai...

CVE-2021-33580

HIGH CVSS 7.5 Aug 18, 2021

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in Apache Roller where user-controlled inputs (Referer header, request URL, and query string) are used to build and exec...

CVE-2024-46911

MEDIUM CVSS 4.7 Oct 14, 2024

This CSRF vulnerability in Apache Roller allows attackers to escalate privileges on multi-blog/user websites. By exploiting the CSRF protection deficiency, attackers can trick authenticated weblog own...