Roller
Vendor:
First CVE: Jul 30, 2009 · Active for 16 years
14
Total CVEs
More Total CVEs than 91% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Roller over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 30, 2009
16 years ago
Most Recent CVE
Apr 14, 2025
468 days ago
CVE Severity & Scoring
Roller14 CVEs
57%
21%
14%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (64.3%)
Unknown5 (35.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (64.3%)
High0 (0.0%)
Unknown5 (35.7%)
User Interaction
None6 (42.9%)
Unknown5 (35.7%)
Required3 (21.4%)
Privileges Required
Low3 (21.4%)
High2 (14.3%)
None4 (28.6%)
Unknown5 (35.7%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4212MEDIUM Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter | Dec 7, 2013 | 6.8 | 78 | NO | YES |
CVE-2014-0030CRITICAL The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. | Oct 10, 2017 | 9.8 | 50 | NO | YES |
CVE-2018-17198CRITICAL Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML- | May 28, 2019 | 9.8 | 32 | NO | NO |
CVE-2025-24859HIGH A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's passwo | Apr 14, 2025 | 8.8 | 28 | NO | NO |
CVE-2021-33580HIGH User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to | Aug 18, 2021 | 7.5 | 25 | NO | NO |
CVE-2012-2380MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins o | Jun 26, 2012 | 6.8 | 23 | NO | NO |
CVE-2019-0234MEDIUM A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to per | Jul 15, 2019 | 6.1 | 22 | NO | NO |
CVE-2015-0249HIGH The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity | Jul 17, 2017 | 7.2 | 20 | NO | NO |
CVE-2024-46911MEDIUM Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitra | Oct 14, 2024 | 4.7 | 18 | NO | NO |
CVE-2024-25090MEDIUM Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms | Jul 26, 2024 | 5.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
14.3% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Roller
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.2.2 | 1 | 6.1 | 3.5% | 0 | 0 |
| 5.2.1 | 2 | 8.0 | 3.8% | 0 | 0 |
| 5.2.0 | 2 | 9.3 | 4.0% | 0 | 0 |
| 5.1.1 | 1 | 7.2 | 4.6% | 0 | 0 |
| 5.1.0 | 1 | 7.2 | 4.6% | 0 | 0 |
| 5.0.2 | 1 | 9.8 | 16.9% | 0 | 1 |
| 5.0.1 | 1 | 9.8 | 16.9% | 0 | 1 |
| 5.0 | 3 | 7.0 | 33.6% | 0 | 2 |
| 4.0.1 | 5 | 6.2 | 21.0% | 0 | 2 |
| 4.0 | 6 | 5.9 | 18.3% | 0 | 2 |
| 3.1 | 4 | 6.1 | 6.5% | 0 | 1 |
| 3.0 | 3 | 4.9 | 3.0% | 0 | 0 |
| 2.3 | 3 | 4.9 | 3.0% | 0 | 0 |
| 2.1.1 | 2 | 5.2 | 2.1% | 0 | 0 |
| 2.1 | 2 | 5.2 | 2.1% | 0 | 0 |
| 2.0.2 | 2 | 5.2 | 2.1% | 0 | 0 |
| 2.0.1 | 2 | 5.2 | 2.1% | 0 | 0 |
| 2.0 | 2 | 5.2 | 2.1% | 0 | 0 |
| 1.3 | 2 | 5.2 | 2.1% | 0 | 0 |
| 1.2 | 2 | 5.2 | 2.1% | 0 | 0 |