CVEs affecting projects tracked on Release Alert, from NVD & OSV.
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.