CVE-2026-102581EPSS p8.7%
CVE-2026-102581CVE-2026-102581
moodle / moodle
Description
A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.
Scoring
| CVSS | 4.6 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |
| EPSS | 0.20% probability of exploitation · percentile 8.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-01 |