SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-80190

MEDIUM · CVSS 6.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Apache Allura is vulnerable to a stored cross-site scripting (XSS) attack via SVN code repositories, potentially allowing attackers to execute malicious scripts in the context of users accessing the affected repositories. This vulnerability does not impact Git repositories and is likely mitigated by default Content Security Policy (CSP) headers. Organizations using Apache Allura versions up to 1.20.0 should prioritize upgrading to version 1.21.0 to address this security issue.

CVE
CVE-2026-80190
Severity
MEDIUM
CVSS
6.1
EPSS
0.19%
Apache

Original NVD Description

Apache Allura: stored XSS via SVN code repositories.  Git repositories are not known to be affected.  The vulnerability is likely mitigated via default CSP headers. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.