Apache Allura
Apache · 15 CVEs
Apache Allura: Stored XSS via code repositories
Sep 4, 2026
Apache Allura: Information exposure via search
Sep 4, 2026
Apache Allura: Server-side request forgery
Sep 4, 2026
Apache Allura: Stored XSS via markdown HTML processing
Sep 4, 2026
Apache Allura: Unauthenticated REST disclosure
Aug 24, 2026
Apache Allura: XSS in markdown pipeline
Aug 12, 2026
Apache Allura: XSS in code display
Aug 12, 2026
Apache Allura: Missing permission checks IDOR
Aug 12, 2026
Apache Allura: Git command injection
Aug 12, 2026
Apache Allura: Server-side request forgery
Aug 11, 2026
Apache Allura: Stored authenticated XSS
Jun 22, 2024
Apache Allura: sensitive information exposure via DNS rebinding
Jun 10, 2024
Apache Allura: sensitive information exposure via import
Nov 7, 2023
In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a mal…
Mar 15, 2018
In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web applicatio…
Feb 6, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-80190 | Apache Allura: Stored XSS via code repositories | MEDIUM | 0.26% | Sep 4, 2026 |
| CVE-2026-81270 | Apache Allura: Information exposure via search | HIGH | 0.43% | Sep 4, 2026 |
| CVE-2026-80181 | Apache Allura: Server-side request forgery | CRITICAL | 0.46% | Sep 4, 2026 |
| CVE-2026-80180 | Apache Allura: Stored XSS via markdown HTML processing | MEDIUM | 0.26% | Sep 4, 2026 |
| CVE-2026-75099 | Apache Allura: Unauthenticated REST disclosure | MEDIUM | 0.57% | Aug 24, 2026 |
| CVE-2026-73237 | Apache Allura: XSS in markdown pipeline | MEDIUM | 0.79% | Aug 12, 2026 |
| CVE-2026-73238 | Apache Allura: XSS in code display | MEDIUM | 0.79% | Aug 12, 2026 |
| CVE-2026-73239 | Apache Allura: Missing permission checks IDOR | MEDIUM | 0.62% | Aug 12, 2026 |
| CVE-2026-73240 | Apache Allura: Git command injection | CRITICAL | 1.04% | Aug 12, 2026 |
| CVE-2026-69223 | Apache Allura: Server-side request forgery | CRITICAL | 0.78% | Aug 11, 2026 |
| CVE-2024-38379 | Apache Allura: Stored authenticated XSS | MEDIUM | 0.69% | Jun 22, 2024 |
| CVE-2024-36471 | Apache Allura: sensitive information exposure via DNS rebinding | HIGH | 0.75% | Jun 10, 2024 |
| CVE-2023-46851 | Apache Allura: sensitive information exposure via import | MEDIUM | 1.65% | Nov 7, 2023 |
| CVE-2018-1319 | In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results m… | MEDIUM | 2.16% | Mar 15, 2018 |
| CVE-2018-1299 | In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with Allura, suc… | HIGH | 3.00% | Feb 6, 2018 |
Showing 1 to 15 of 15 CVEs