SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-80180

MEDIUM · CVSS 6.1 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Apache Allura versions up to 1.20.0 are vulnerable to a stored cross-site scripting (XSS) attack due to improper handling of markdown HTML processing. This vulnerability could allow an attacker to inject malicious scripts, potentially compromising user data and session integrity. Organizations using Apache Allura should prioritize upgrading to version 1.21.0 to mitigate this risk.

CVE
CVE-2026-80180
Severity
MEDIUM
CVSS
6.1
EPSS
0.20%
Apache

Original NVD Description

Stored XSS via markdown HTML processingĀ in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to versionĀ 1.21.0, which fixes the issue.