XSS Vulnerability in Apache Allura Affects User Code Display
CVE-2026-73238

6.1MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
12 August 2026

What is CVE-2026-73238?

An XSS vulnerability has been identified in the code display feature of Apache Allura, which could allow attackers to inject malicious scripts. This issue affects all versions prior to 1.19.1. Users are strongly advised to upgrade to version 1.19.1 or later to mitigate the risk of exploitation.

Affected Version(s)

Apache Allura 0 < 1.19.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.