Looking for the vulnerability index of Invicti's legacy products?
Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2025-26528 - Vulnerability Database

Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2025-26528

Medium
Reference: CVE-2025-26528
Title: Moodle Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.