CVE-2021-47857 MEDIUM

CVE-2021-47857: Moodle 3.10.3 - 'label' Persistent Cross Site Scripting

Vendor Moodle
Product Moodle
Weakness CWE-79 · XSS
Published January 21, 2026
Last update March 5, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.

Key dates

02Disclosure timeline

January 21, 2026 CVE published
March 5, 2026 Record updated