Stored XSS Vulnerability in Moodle Forum Posts
CVE-2026-102581

4.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102581?

A vulnerability in Moodle has been identified that allows insufficient output escaping in templates for forum posts. This security issue permits attackers to inject malicious scripts into forum content, which can be executed in the browsers of users accessing those posts. Successful exploitation can lead to unauthorized actions and exposure of sensitive user data, highlighting the necessity for immediate security updates and awareness among Moodle users.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Lars Bonczek as the original reporter.
.