Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.
https://lists.apache.org/thread/rjo2hjhp76qhl9f3br8jq909mohvzkpq