CVE-2025-26530: Reflected XSS via question bank filter
The question bank filter required additional sanitizing to prevent a reflected XSS risk.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.3.10 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.4.6 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.5.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26530?
The severity of CVE-2025-26530 is classified as medium due to the potential for reflected XSS attacks.
How do I fix CVE-2025-26530?
To fix CVE-2025-26530, upgrade to Moodle version 4.3.10, 4.4.6, or 4.5.2 or later.
What software is affected by CVE-2025-26530?
CVE-2025-26530 affects Moodle versions from 4.3.0-beta up to 4.3.10, and from 4.4.0-beta to 4.4.6, as well as from 4.5.0-beta to 4.5.2.
What type of attack does CVE-2025-26530 allow?
CVE-2025-26530 allows for reflected Cross-Site Scripting (XSS) attacks due to insufficient sanitization of the question bank filter.
Is there a workaround for CVE-2025-26530?
There is no specific workaround recommended for CVE-2025-26530; upgrading to the fixed versions is advised.