Overview
- Apache Software Foundation
- Apache Allura
04 Sep 2026
Published
04 Sep 2026
Updated
CVSS
Pending
EPSS
0.21%
KEV
Description
Stored XSS via markdown HTML processing in Apache Allura.
This issue affects Apache Allura: from through 1.20.0.
Users are recommended to upgrade to version 1.21.0, which fixes the issue.
Statistics
- 1 Post
Last activity: 21 hours ago
Fediverse
Apache released version 1.21.0 to patch critical Apache Allura security vulnerabilities. Update now to protect against XSS, SSRF, and data exposure flaws.
#ApacheAllura #CyberSecurity #CVE202680180 #CVE202680181 #CVE202681270