Description
A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.
Published: 2026-09-30
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting in forum posts
Action: Patch
AI Analysis

Impact

The vulnerability arises from insufficient escaping in Moodle’s forum post templates, allowing an attacker to store malicious scripts that execute in the browsers of other users who view the affected post. This stored XSS flaw can be used to hijack user sessions, deface content, or deliver additional malware. The weakness is a classic example of input validation failure (CWE‑79).

Affected Systems

Moodle installations are affected. No specific version range is provided in the available data, so all releases remain potentially vulnerable until a patch is applied. The flaw impacts any user who can post content that will be displayed in the forum display templates.

Risk and Exploitability

The CVSS score of 4.6 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited broad exploitation evidence to date. However, the attack vector is likely through normal user interaction: an attacker posts a crafted forum entry, and any subsequent user viewing that post is exposed. Compatibility and permissions are typically local to the Moodle instance, so the attack surface is confined to the user base that has access to the forum.

Generated by OpenCVE AI on September 30, 2026 at 11:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Moodle to the latest released version that contains the output‑escaping fix; check the official Moodle repository or Red Hat advisories for the patch details.
  • If an upgrade is not immediately possible, temporarily disable the forum module or block public posting until a fix is applied to prevent new malicious content from being stored.
  • As a temporary defense, configure a strict Content Security Policy that blocks inline scripts in forum pages and enforce server‑side output encoding for any retained user content.

Generated by OpenCVE AI on September 30, 2026 at 11:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Vendors & Products Moodle
Moodle moodle

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.
Title Moodle: xss in forum post templates due to insufficient escaping
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-30T14:35:11.793Z

Reserved: 2026-09-29T14:03:38.494Z

Link: CVE-2026-102581

cve-icon Vulnrichment

Updated: 2026-09-30T14:35:07.872Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T09:17:15.213

Modified: 2026-09-30T16:20:44.613

Link: CVE-2026-102581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')