Apache Allura
Apache Software Foundation- Product type
- Other
- Catalog vulnerabilities
- 15
Severity across 15 analyzed records
Verify to analyze this security profile
en
Severity across 15 analyzed records
Verify to analyze this security profile
As of 09/15/2026, within CyStack's analyzed data, Apache Allura has 10 security vulnerabilities published in the last 90 days. Of these, 4 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Apache Allura and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-80190Apache Allura: Stored XSS via code repositories | Exploitation statusNot known exploited | FixYes | Published09/04/2026 | SeverityMedium |
CVE-2026-81270Apache Allura: Information exposure via search | Exploitation statusNot known exploited | FixYes | Published09/04/2026 | SeverityHigh |
CVE-2026-80181Apache Allura: Server-side request forgery | Exploitation statusNot known exploited | FixYes | Published09/04/2026 | SeverityCritical |
CVE-2026-80180Apache Allura: Stored XSS via markdown HTML processing | Exploitation statusNot known exploited | FixYes | Published09/04/2026 | SeverityMedium |
CVE-2026-75099Apache Allura: Unauthenticated REST disclosure | Exploitation statusNot known exploited | FixYes | Published08/24/2026 | SeverityMedium |
CVE-2026-73237Apache Allura: XSS in markdown pipeline | Exploitation statusNot known exploited | FixYes | Published08/12/2026 | SeverityMedium |
CVE-2026-73238Apache Allura: XSS in code display | Exploitation statusNot known exploited | FixYes | Published08/12/2026 | SeverityMedium |
CVE-2026-73239Apache Allura: Missing permission checks IDOR | Exploitation statusNot known exploited | FixYes | Published08/12/2026 | SeverityMedium |
CVE-2026-73240Apache Allura: Git command injection | Exploitation statusNot known exploited | FixYes | Published08/12/2026 | SeverityCritical |
CVE-2026-69223Apache Allura: Server-side request forgery | Exploitation statusNot known exploited | FixYes | Published08/11/2026 | SeverityCritical |
CVE-2024-38379Apache Allura: Stored authenticated XSS | Exploitation statusNot known exploited | FixYes | Published06/22/2024 | SeverityMedium |
CVE-2024-36471Apache Allura: sensitive information exposure via DNS rebinding | Exploitation statusNot known exploited | FixYes | Published06/10/2024 | SeverityHigh |
CVE-2023-46851Apache Allura: sensitive information exposure via import | Exploitation statusNot known exploited | FixYes | Published11/07/2023 | SeverityUnknown |
CVE-2018-1319 | Exploitation statusNot confirmed | FixNot confirmed | Published03/15/2018 | SeverityUnknown |
CVE-2018-1299 | Exploitation statusNot confirmed | FixNot confirmed | Published02/06/2018 | SeverityUnknown |