Cross-site scripting in Apache Allura - CVE-2026-80180
Published: September 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in markdown HTML processing when rendering stored markdown content. A remote attacker can inject a specially crafted markdown payload to execute arbitrary script code in a victim's browser.