Stored XSS in Apache Allura Affecting Users
CVE-2026-80180

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
4 September 2026

What is CVE-2026-80180?

Apache Allura is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability that arises from improper handling of markdown HTML processing. An attacker may exploit this flaw to inject malicious scripts, which could be executed when unsuspecting users interact with impacted pages. To mitigate the risk associated with this vulnerability, users are advised to upgrade to version 1.21.0, as it addresses and resolves the underlying issue.

Affected Version(s)

Apache Allura 0 <= 1.20.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k
.