Total vulnerabilities in the database
In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.
CVSS v3:
CWEs:
OWASP TOP 10: