https://seclists.org/oss-sec/2026/q3/643: CVE-2026-80180: Apache Allura: Stod XSS via markdown HTML processing
Published Sep 3, 2026
·Updated
Affected Software
1 affected component
Apache Allura<=1.20.0
Frequently Asked Questions
1
Which installations need to be upgraded?
Apache Allura versions through 1.20.0 are affected. Upgrade to version 1.21.0, which fixes the issue.
2
What type of attack should administrators investigate?
The issue is stored cross-site scripting through markdown HTML processing. Administrators should investigate content that may have been saved through markdown processing.