VDB
CVE-2025-26530
CVE-2025-26530
PUBLISHED
The question bank filter required additional sanitizing to prevent a reflected XSS risk.
EPSS 0.96% · 76.8th percentile
Risk Scores
EPSS Score
0.96%
76.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | moodle | 4.3.0, 4.4.0, 4.5.0 |
| Bitnami | moodle | 4.3.0, 4.4.0, 4.5.0 |
Exploit Intelligence
- CIRCL seen: CVE-2025-26530 (circl-sighting)
- CIRCL seen: CVE-2025-26530 (circl-sighting)
- https://moodle.org/mod/forum/discuss.php?d=466146 (circl)
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84146 (circl)
Timeline
- Feb 17, 2025 CVE Published
- Feb 24, 2025 Coalition ESS Score
- Feb 24, 2025 PoC Published
- Feb 24, 2025 PoC Published
- Feb 25, 2025 Coalition ESS Score
- Feb 27, 2025 EPSS Score
- Mar 13, 2025 EPSS Score
- Mar 27, 2025 EPSS Score
- Apr 10, 2025 EPSS Score
- Apr 24, 2025 EPSS Score
- May 8, 2025 EPSS Score
- May 22, 2025 EPSS Score