CVE-2026-102586Medium· 4.3▾ SunlitA flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially craft…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access a specially crafted password reset link, an attacker could execute arbitrary script in the victim's browser.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102581Medium· 4.6A flaw was found in Moodle
CVE-2026-102579Medium· 4.3A flaw was found in Moodle
CVE-2026-102577Medium· 4.3A flaw was found in Moodle
CVE-2026-102578Medium· 5.5A flaw was found in Moodle
CVE-2026-102585Medium· 4.3A flaw was found in Moodle
CVE-2026-102582Low· 2.2A flaw was found in Moodle