CVE detail
CVE-2022-50943
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- https://www.vulncheck.com/advisories/moodle-lms-cross-site-scripting-via-course-search-phpwww.vulncheck.com
No excerpt available.
Exploitwww.vulncheck.comMay 10, 2026, 1:16 PM - https://www.exploit-db.com/exploits/51115www.exploit-db.com
No excerpt available.
Exploitwww.exploit-db.comMay 10, 2026, 1:16 PM - https://moodle.org/moodle.org
No excerpt available.
Productmoodle.orgMay 10, 2026, 1:16 PM - https://git.in.moodle.com/moodlegit.in.moodle.com
No excerpt available.
Productgit.in.moodle.comMay 10, 2026, 1:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-67855CVSS 5.4 · Medium
A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This vulnerability arises from ins…
- CVE-2025-67850CVSS 7.3 · High
A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic exp…
- CVE-2025-67849CVSS 7.3 · High
A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or scr…
- CVE-2021-47857CVSS 5.1 · Medium
Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft…
- CVE-2025-3643CVSS 5.4 · Medium
A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.
- CVE-2025-26530CVSS 8.3 · High
The question bank filter required additional sanitizing to prevent a reflected XSS risk.