Medium severity4.6NVD Advisory· Published Sep 30, 2026
CVE-2026-102581
CVE-2026-102581
Description
A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.