CVE-2026-102581 - Moodle: xss in forum post templates due to insufficient escaping
CVE ID :CVE-2026-102581
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102581
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then executes arbitrary script code in the browser of another user viewing the affected post.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102582 - Moodle: manual enrolment page accessible when plugin disabled
CVE ID :CVE-2026-102582
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.
Severity: 2.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102582
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage manual enrolments even after an administrator disabled the feature in the user interface.
Severity: 2.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102583 - Moodle: incorrect capability check in ai generate image web service
CVE ID :CVE-2026-102583
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102583
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to access and utilize the AI image generation functionality.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102584 - Moodle: missing capability check allows unauthorised grade penalty recalculation
CVE ID :CVE-2026-102584
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102584
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, potentially altering student assessment scores.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102585 - Moodle: group validation missing when enrolling user to course
CVE ID :CVE-2026-102585
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102585
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher privileges could exploit this flaw to add users to groups within courses they do not have authorization to access.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102586 - Moodle: xss via password reset link due to insufficient username escaping
CVE ID :CVE-2026-102586
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102586
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102587 - Moodle: user list filters bypass profile field visibility
CVE ID :CVE-2026-102587
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102587
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized information disclosure by inferring hidden user data.
Severity: 2.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102588 - Moodle: csrf in xml grade import
CVE ID :CVE-2026-102588
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102588
Published : Sept. 30, 2026, 8:36 a.m. | 52 minutes ago
Description :A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an attacker can trigger unauthorized requests on the victim's behalf. This flaw allows a remote attacker to set or overwrite student grades without authorization.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97288 - WordPress OAuth Server plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-97288
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97288
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97289 - WordPress Quiz And Survey Master plugin <= 11.2.6 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-97289
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97289
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97292 - WordPress YITH WooCommerce Tab Manager plugin <= 2.15.0 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-97292
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97292
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97293 - WordPress Media LIbrary Assistant plugin <= 3.41 - SQL Injection vulnerability
CVE ID :CVE-2026-97293
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97293
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97298 - WordPress King Addons for Elementor plugin <= 51.1.86 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-97298
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97298
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97299 - WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-97299
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97299
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97301 - WordPress Cool Formkit Lite plugin <= 2.7.8 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-97301
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97301
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97302 - WordPress MPG plugin <= 4.2.3 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-97302
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97302
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100507 - WordPress If-So Dynamic Content Personalization plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-100507
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100507
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100508 - WordPress Two Factor plugin <= 0.16.0 - Denial of Service Attack vulnerability
CVE ID :CVE-2026-100508
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100508
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100513 - WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-100513
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100513
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102384 - WordPress Supreme Modules Lite plugin <= 2.5.63 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-102384
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102384
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102385 - WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-102385
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102385
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...