CVE-2026-80190
- EPSS 0.19%
- Veröffentlicht 04.09.2026 07:06:19
- Zuletzt bearbeitet 08.09.2026 14:00:01
Apache Allura: stored XSS via SVN code repositories. Git repositories are not known to be affected. The vulnerability is likely mitigated via default CSP headers. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgr...
CVE-2026-81270
- EPSS 0.39%
- Veröffentlicht 04.09.2026 06:59:49
- Zuletzt bearbeitet 08.09.2026 14:00:01
Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.
CVE-2026-80181
- EPSS 0.21%
- Veröffentlicht 04.09.2026 06:52:42
- Zuletzt bearbeitet 08.09.2026 19:19:53
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.
CVE-2026-80180
- EPSS 0.2%
- Veröffentlicht 04.09.2026 06:50:14
- Zuletzt bearbeitet 08.09.2026 14:00:01
Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.
CVE-2026-75099
- EPSS 0.23%
- Veröffentlicht 24.08.2026 16:42:20
- Zuletzt bearbeitet 28.08.2026 17:54:22
Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the issue.
CVE-2026-73237
- EPSS 0.43%
- Veröffentlicht 12.08.2026 16:42:27
- Zuletzt bearbeitet 17.08.2026 19:10:03
XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
CVE-2026-73238
- EPSS 0.43%
- Veröffentlicht 12.08.2026 16:41:58
- Zuletzt bearbeitet 17.08.2026 19:09:53
XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
CVE-2026-73239
- EPSS 0.34%
- Veröffentlicht 12.08.2026 16:41:41
- Zuletzt bearbeitet 17.08.2026 19:09:42
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
CVE-2026-73240
- EPSS 0.54%
- Veröffentlicht 12.08.2026 16:41:19
- Zuletzt bearbeitet 17.08.2026 19:08:51
Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
CVE-2026-69223
- EPSS 0.73%
- Veröffentlicht 11.08.2026 17:03:04
- Zuletzt bearbeitet 17.08.2026 19:09:32
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.