Stored XSS in Apache Allura Affecting Users
CVE-2026-80180
Currently unrated
What is CVE-2026-80180?
Apache Allura is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability that arises from improper handling of markdown HTML processing. An attacker may exploit this flaw to inject malicious scripts, which could be executed when unsuspecting users interact with impacted pages. To mitigate the risk associated with this vulnerability, users are advised to upgrade to version 1.21.0, as it addresses and resolves the underlying issue.
Affected Version(s)
Apache Allura 0 <= 1.20.0