Vulnerability Research

CVE discoveries and responsible disclosure stories

CVE-2025-60506 | Stored Cross-Site Scripting (XSS) in Moodle PDF Annotator plugin (v1.5 release 9)

Penetration Testing

CVE-2025-60506 | Stored Cross-Site Scripting (XSS) in Moodle PDF Annotator plugin (v1.5 release 9)

Date: 17-Oct-2025 Tags: Cybersecurity, responsible-disclosure, penetration-testing Summary * Vulnerability: Stored Cross-Site Scripting (XSS) in Moodle PDF Annotator plugin (mod_pdfannotator) — Public Comments rendering. * CVE: CVE-2025-60506 (assigned) * Discoverer: Onurcan Genç — Independent Security Researcher * Tested environment: Bitnami Docker image for Moodle 4.x * Plugin: mod_pdfannotator v1.5 (release 9, build 2025090300) * Browser

By Onurcan Genç