Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102581— Moodle: xss in forum post templates due to insufficient escaping

Quick assessment

Affected
CVE-2026-102581
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Moodle 中发现了一个漏洞。用于显示论坛帖子的模板中存在输出转义不足的问题,导致存储型跨站脚本(XSS)漏洞。攻击者可以将恶意内容注入到论坛帖子中,当其他用户浏览该受影响帖子时,其浏览器会执行任意脚本代码。

CVSS 4.6 · Medium EPSS 0.20% · P9

Possible ATT&CK Techniques 1 AI

T1059.007 · JavaScript

Affected Version Matrix 4

VendorProduct Version RangeStatus
None None 5.2.0< 5.2.2 affected
5.1.0< 5.1.6 affected
5.0.0< 5.0.9 affected
< 4.5.13 affected

I. Basic Information for CVE-2026-102581

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Moodle: xss in forum post templates due to insufficient escaping
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 5.2.0 ~ 5.2.2 -

II. Public POCs for CVE-2026-102581

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102581

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-102581 (1)

Vendor Advisories for CVE-2026-102581 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-102581

No comments yet


Leave a comment