Roller

Vendor:

First CVE: Jul 30, 2009 · Active for 16 years

14
Total CVEs
More Total CVEs than 91% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Roller over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 30, 2009
16 years ago
Most Recent CVE
Apr 14, 2025
468 days ago

CVE Severity & Scoring

Roller14 CVEs
All CVEs352,719 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (64.3%)
Unknown5 (35.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (64.3%)
High0 (0.0%)
Unknown5 (35.7%)
User Interaction
None6 (42.9%)
Unknown5 (35.7%)
Required3 (21.4%)
Privileges Required
Low3 (21.4%)
High2 (14.3%)
None4 (28.6%)
Unknown5 (35.7%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter
Dec 7, 20136.878NOYES
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Oct 10, 20179.850NOYES
Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-
May 28, 20199.832NONO
A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's passwo
Apr 14, 20258.828NONO
User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression. The attacker doesn't have to
Aug 18, 20217.525NONO
Multiple cross-site request forgery (CSRF) vulnerabilities in the admin/editor console in Apache Roller before 5.0.1 allow remote attackers to hijack the authentication of admins o
Jun 26, 20126.823NONO
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to per
Jul 15, 20196.122NONO
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity
Jul 17, 20177.220NONO
Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websites, by default weblog owners are trusted to publish arbitra
Oct 14, 20244.718NONO
Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms
Jul 26, 20245.418NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
14.3% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Roller

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.2.216.13.5%00
5.2.128.03.8%00
5.2.029.34.0%00
5.1.117.24.6%00
5.1.017.24.6%00
5.0.219.816.9%01
5.0.119.816.9%01
5.037.033.6%02
4.0.156.221.0%02
4.065.918.3%02
3.146.16.5%01
3.034.93.0%00
2.334.93.0%00
2.1.125.22.1%00
2.125.22.1%00
2.0.225.22.1%00
2.0.125.22.1%00
2.025.22.1%00
1.325.22.1%00
1.225.22.1%00