CVE-2026-102581
Received Received - Intake

Stored XSS in Moodle Forum Post Templates

Vulnerability report for CVE-2026-102581, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Fedora Project

Description

A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moodle moodle *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in Moodle. It occurs because templates used to display forum posts do not properly escape user input. An attacker can inject malicious scripts into a forum post, which then executes in the browsers of users who view the post.

Detection Guidance

To detect this stored XSS vulnerability in Moodle, inspect forum posts for suspicious scripts or HTML tags. Check browser console logs for errors when viewing forum pages. Use tools like OWASP ZAP or Burp Suite to scan for XSS vulnerabilities in Moodle's forum functionality.

Impact Analysis

If exploited, this vulnerability could allow an attacker to execute arbitrary scripts in your browser when viewing a malicious forum post. This may lead to session hijacking, unauthorized code execution, or theft of your data.

Compliance Impact

This vulnerability could lead to serious consequences such as session hijacking, unauthorized code execution, or data theft if exploited. Such breaches may result in non-compliance with GDPR or HIPAA, as unauthorized access to personal or health data could occur. The stored XSS allows attackers to bypass protection mechanisms and read application data, which may violate data protection requirements under these regulations.

Mitigation Strategies

Update Moodle to the latest version to patch the vulnerability. Review and sanitize existing forum posts for malicious scripts. Implement input validation and output escaping in Moodle's forum templates. Monitor forum activity for unusual content or behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102581. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart