Apache Allura

4 known vulnerabilities in Apache Allura, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-80190 CVSS 6.1 medium Apache Allura: stored XSS via SVN code repositories. Git repositories are not known to be affected. The vulnerability is likely mitigated…
  • CVE-2026-81270 CVSS 7.5 high Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to…
  • CVE-2026-80181 CVSS 9.1 critical Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are…
  • CVE-2026-80180 CVSS 6.1 medium Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to…