CVE-2026-102581 PUBLISHED

Moodle: xss in forum post templates due to insufficient escaping

Assigner: fedora
Reserved: 29.09.2026 Published: 30.09.2026 Updated: 30.09.2026

A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CVSS Score: 4.6

Product Status

Package Collection https://git.moodle.org
Package Name moodle
Versions Default: unaffected
  • affected from 5.2.0 to 5.2.2 (excl.)
  • affected from 5.1.0 to 5.1.6 (excl.)
  • affected from 5.0.0 to 5.0.9 (excl.)
  • affected from 0 to 4.5.13 (excl.)

Credits

  • Upstream acknowledges Lars Bonczek as the original reporter.

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE