CVE-2022-50943: Moodle

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.

Affected products

  • Moodle Moodle: up to and including 4.0.0

Published 2026-05-10. Last modified 2026-07-25.