Stored XSS Vulnerability in Apache Allura by Apache
CVE-2026-80190
Currently unrated
What is CVE-2026-80190?
Apache Allura has been identified with a stored XSS vulnerability that exploits SVN code repositories. Git repositories remain unaffected. This vulnerability could allow attackers to execute scripts in the context of a user's session. It is recommended that users upgrade to version 1.21.0 as it addresses the issue effectively. The risk associated with this vulnerability is likely mitigated through default Content Security Policy (CSP) headers.
Affected Version(s)
Apache Allura 0 <= 1.20.0