MDL Shield
Version checkMoodle 3.1.9

Moodle 3.1.9 3.1 no longer receives security fixesLTS

Released 13 Nov 2017. Moodle 3.1 had its last security release, 3.1.18, on 13 May 2019, and its security support ended 13 May 2019. Advisories published since then list it only as an earlier unsupported version.

284 security advisories since 3.1.9

262 of them were published after 3.1 left security support, so no 3.1 release fixes them. The fix is a major upgrade: 4.5.14 is the current long-term support release, 5.2.3 the newest.

284
Advisories
121
Serious
163
Minor
262
Not fixed in 3.1
17
CVE pending
Group by
284 advisories, newest first
Serious121

The XML grade import functionality (which allows setting or overwriting of student grades) did not include the necessary token to prevent a CSRF risk.

CVE pendingMDL-84545Not fixed on 3.19 Sep 2026moodle.org

User profile descriptions for authenticated users posed a denial of service risk due to the absence of a defined maximum length.

CVE-2026-58347MDL-87898Not fixed on 3.122 Jun 2026moodle.org

The grade item ID number editing functionality did not include the necessary token to prevent a CSRF risk and also lacked sufficient output sanitizing to prevent an XSS risk.

CVE-2026-58340MDL-88542Not fixed on 3.122 Jun 2026moodle.org

Additional checks were required to ensure users with the capability to delete comments can only do so in the contexts where they have the permission.

CVE-2026-58336MDL-88619Not fixed on 3.122 Jun 2026moodle.org

A remote code execution risk was identified in the admin presets import feature. Note: This feature is only available to site administrators.

CVE-2026-58334MDL-88735Not fixed on 3.122 Jun 2026moodle.org
SeriousMSA-26-0013Email-based MFA bypass

A flaw in email-based multi-factor authentication made it possible for a user to bypass another user's MFA token check if using the email factor. Note: Valid login credentials (such as username and password) were still required to log into the account.

CVE-2026-58332MDL-88767Not fixed on 3.122 Jun 2026moodle.org

Insufficient state and capability checks resulted in some details of hidden courses (such as course name, description and teachers) being available to users who did not have permission to access them.

CVE-2025-49515MDL-84518Not fixed on 3.117 Jun 2025moodle.org
SeriousMSA-25-0032SSRF risk via DNS rebind

A DNS rebind risk in the way cURL requests were handled could result in an SSRF risk, due to the possibility of cURL blocked hosts / allowed ports site configurations being bypassed.

CVE-2025-49514MDL-83762Not fixed on 3.117 Jun 2025moodle.org

The upstream ADOdb library contained an SQL injection risk in the pg_insert_id() method. It is important to note that the core Moodle LMS was NOT affected by this vulnerability, however as a precaution, this library has been upgraded to remove the risk entirely, in case any third party code/plugins uses the vulnerable code.

CVE-2025-46337MDL-85375Not fixed on 3.117 Jun 2025moodle.org

Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.

CVE-2025-26529MDL-84145Not fixed on 3.118 Feb 2025moodle.org

Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).

CVE-2025-26525MDL-84136Not fixed on 3.118 Feb 2025moodle.org

Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).

CVE-2024-43426MDL-82745Not fixed on 3.119 Aug 2024moodle.org
SeriousMSA-23-0045DOS risk in URL downloader

Insufficient recursion limitations resulted in a denial of service risk in the URL downloader.

CVE-2023-6662MDL-79759Not fixed on 3.121 Dec 2023moodle.org

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.

CVE-2023-5550MDL-72249Not fixed on 3.117 Oct 2023moodle.org

Insufficient path checks in a lesson question import resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

CVE-2022-35650MDL-72029Not fixed on 3.118 Jul 2022moodle.org

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

CVE-2022-0983MDL-74074Not fixed on 3.121 Mar 2022moodle.org

Insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk. ( Note: The request response was still blocked and not available to the user.)

CVE-2021-36396MDL-71916Not fixed on 3.119 Jul 2021moodle.org

An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair.

CVE-2021-32474MDL-70804Not fixed on 3.117 May 2021moodle.org

The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk.

CVE-2020-25628MDL-69340Not fixed on 3.121 Sep 2020moodle.org

It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution.

CVE-2020-10738MDL-68410Not fixed on 3.118 May 2020moodle.org

Authenticated user are allowed to add HTML blocks containing scripts to their Dashboard and this is normally not a security issue because personal dashboard is visible to this user only. Through this security vulnerability users can move such block to other pages where they can be viewed by other users.

CVE-2018-1136MDL-62206Fixed in 3.1.1225 May 2018moodle.org

By substituting the source URL in the filepicker AJAX request authenticated users are able to retrieve and view any URL. We classify this issue as serious because some cloud hosting providers contain internal resources that can expose data and compromise a server

CVE-2018-1042MDL-61131Fixed in 3.1.1022 Jan 2018moodle.org
Minor163

Insufficient username escaping could allow a minor XSS risk if an unauthenticated user was tricked into opening a password reset link (so did not affect authenticated user sessions).

CVE pendingMDL-88335Not fixed on 3.19 Sep 2026moodle.org

The report builder fragment output callbacks did not verify that the requesting user had the required capability to access the requested report, potentially allowing users to retrieve report data beyond their permitted access.

CVE-2026-58348MDL-84535Not fixed on 3.122 Jun 2026moodle.org

A blind SSRF risk was identified in the MNet peers management functionality, due to missing validation of peer hostnames against the cURL blocked hosts configuration. Note: This feature is only available to site administrators.

CVE-2026-58346MDL-87911Not fixed on 3.122 Jun 2026moodle.org

Capability checks were missing from course assistance AI placement web services, which could allow users to make requests to those AI course assistance web services without having the relevant capabilities (if those features are enabled).

CVE-2026-58343MDL-88533Not fixed on 3.122 Jun 2026moodle.org

Missing group access checks in some grade web services could allow a user to access grade and user information for students in groups they did not have permission to view.

CVE-2026-58335MDL-88667Not fixed on 3.122 Jun 2026moodle.org

Separate Groups mode restrictions were not honoured when viewing a course's Logs report, so actions of all course participants were displayed in the report. By default this only provided additional access to non-editing teachers.

CVE-2025-62436MDL-84464Not fixed on 3.121 Aug 2025moodle.org

The "move up" and "move down" actions in backpack management for badges did not include the necessary token to prevent a CSRF risk.

CVE-2025-49516MDL-84497Not fixed on 3.117 Jun 2025moodle.org

In a database activity with separate groups mode enabled, users who were not in a group (and did not have permission to access all groups) could see entries from members of all groups in the activity, rather than just entries of users also not in any groups. Note: Users within groups worked as intended, only able to see entries belonging to other members of their group(s).

CVE-2024-55646MDL-82757Not fixed on 3.117 Dec 2024moodle.org

On sites requiring a confirmation step to update a user's email address, the token used to verify the change should only be accessible via the confirmation email, but was otherwise retrievable by the user.

CVE-2024-55645MDL-82379Not fixed on 3.117 Dec 2024moodle.org

Additional checks were required to ensure users can only access the schedule of a report if they have permission to edit that report.

CVE-2024-48901MDL-83180Not fixed on 3.114 Oct 2024moodle.org

Additional checks were required to ensure users can only edit or delete RSS feeds they have permission to modify.

CVE-2024-48897MDL-82386Not fixed on 3.114 Oct 2024moodle.org

It was possible for users with the "send message" capability to view other users' names they may not otherwise have access to, via an error message in Messaging. (Note: The name returned followed the full name format configured on the site).

CVE-2024-48896MDL-83352Not fixed on 3.114 Oct 2024moodle.org

The cURL wrapper in Moodle stripped HTTPAUTH and USERPWD headers during emulated redirects, but retained other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

CVE-2024-43432MDL-82136Not fixed on 3.119 Aug 2024moodle.org

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (eg on their profile page).

CVE-2024-25983MDL-78300Not fixed on 3.119 Feb 2024moodle.org

Separate Groups mode restrictions were not honoured when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

CVE-2024-25981MDL-80504Not fixed on 3.119 Feb 2024moodle.org

The JQuery UI library included with Moodle has been upgraded to version 1.13.2, which includes fixes for security issues.

CVE-2022-31160, CVE-2021-41184, CVE-2021-41183, CVE-2021-41182MDL-74544Not fixed on 3.121 Aug 2023moodle.org

The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

CVE-2023-28333MDL-75659Not fixed on 3.120 Mar 2023moodle.org

The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

CVE-2022-40316MDL-71662Not fixed on 3.119 Sep 2022moodle.org

The analytics Python Machine Learning backend has received some security fixes, resulting in the required PIP package version being increased. ( Note: Sites using the PHP ML backend, or not using analytics are not affected)

CVE pendingMDL-66069Not fixed on 3.116 Sep 2019moodle.org

The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.

CVE-2019-3809MDL-64222Fixed in 3.1.1621 Jan 2019moodle.org

The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.

CVE-2019-3808MDL-64395Fixed in 3.1.1621 Jan 2019moodle.org

A security vulnerability was reported against QuickForm, a third party library used by Moodle. Although no attack vector was identified within our software, Moodle has updated to patched versions of QuickForm as a precaution.

CVE-2018-1999022MDL-62947Fixed in 3.1.1417 Sep 2018moodle.org

It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories. Note this only affects cases where a user has access to manage categories, but does not also have permission to view hidden categories.

CVE-2018-10890MDL-62790Fixed in 3.1.1316 Jul 2018moodle.org

It is possible to inject javascript in the event name in the calendar block. Normally capability to create events is only given to trusted users (such as teachers), however it is not marked as having XSS risk, therefore it is considered a security issue.

CVE-2018-1045MDL-60235Fixed in 3.1.1022 Jan 2018moodle.org
You are here: Moodle 3.1.9
Released 13 Nov 2017. Each release below closes the advisories listed under it.
Moodle 3.1.1015 Jan 2018 · 3 advisories1 Serious2 Minor
MinorMSA-18-0004XSS in calendar event nameCVE-2018-1045MDL-60235moodle.org
MinorMSA-18-0003Privilege escalation in quiz web servicesCVE-2018-1044MDL-60908moodle.org
SeriousMSA-18-0001Server Side Request Forgery in the filepickerCVE-2018-1042MDL-61131moodle.org
Moodle 3.1.1119 Mar 2018 · 1 advisory1 Serious
Moodle 3.1.139 Jul 2018 · 2 advisories2 Minor
Moodle 3.1.1410 Sep 2018 · 2 advisories1 Serious1 Minor
Moodle 3.1.1512 Nov 2018 · 1 advisory1 Serious
SeriousMSA-18-0020Login CSRF vulnerability in login formCVE-2018-16854MDL-63183moodle.org
Moodle 3.1.1614 Jan 2019 · 3 advisories3 Minor
Moodle 3.1.1711 Mar 2019 · 2 advisories1 Serious1 Minor
Moodle 3.1.1813 May 2019 · 2 advisoriesLast release2 Minor
No 3.1 releasePublished after 13 May 2019, when 3.1 left security support · 262 advisories113 Serious149 Minor
SeriousMSA-26-0041CSRF risk in XML grade importsCVE pendingMDL-84545moodle.org
MinorMSA-26-0039Minor XSS risk via password reset linkCVE pendingMDL-88335moodle.org
MinorMSA-26-0034XSS risk in forum post templatesCVE pendingMDL-88981moodle.org
SeriousMSA-26-0031SQL injection risk in question bank web serviceCVE pendingMDL-89383moodle.org
SeriousMSA-26-0028DoS risk via user profile descriptionCVE-2026-58347MDL-87898moodle.org
MinorMSA-26-0027Blind SSRF risk in MNet peers functionCVE-2026-58346MDL-87911moodle.org
SeriousMSA-26-0025CSRF risk in quiz attempt regradingCVE-2026-58344MDL-88531moodle.org
MinorMSA-26-0023CSRF risk when adding quiz section headingsCVE-2026-58342MDL-88540moodle.org
MinorMSA-26-0022CSRF risk in group messaging state toggleCVE-2026-58341MDL-88541moodle.org
SeriousMSA-26-0021CSRF and XSS in grade item idnumber editingCVE-2026-58340MDL-88542moodle.org
MinorMSA-26-0020Reflected XSS via Feedback import error messageCVE-2026-58339MDL-88543moodle.org
MinorMSA-26-0019CSRF risk in user profile page resetCVE-2026-58338MDL-88545moodle.org
MinorMSA-26-0018CSRF risk in user homepage preference settingCVE-2026-58337MDL-88609moodle.org
SeriousMSA-26-0017IDOR allows arbitrary comment deletionCVE-2026-58336MDL-88619moodle.org
SeriousMSA-26-0015RCE risk via admin presets importCVE-2026-58334MDL-88735moodle.org
SeriousMSA-26-0014Arbitrary file read risk in backup restoreCVE-2026-58333MDL-88736moodle.org
SeriousMSA-26-0013Email-based MFA bypassCVE-2026-58332MDL-88767moodle.org
SeriousMSA-26-0003Denial of service risk in TeX formula editorCVE-2026-26047MDL-86785moodle.org
SeriousMSA-26-0001Remote code execution risk via file restoreCVE-2026-26045MDL-87612moodle.org
SeriousMSA-25-0059Reflected XSS risk in policy toolCVE-2025-67855MDL-86544moodle.org
MinorMSA-25-0056Open redirect in OAuth loginCVE-2025-67852MDL-80317moodle.org
SeriousMSA-25-0054XSS risk in formula editorCVE-2025-67850MDL-85557moodle.org
SeriousMSA-25-0051Remote code execution risk via file restoreCVE-2025-67847MDL-87353moodle.org
MinorMSA-25-0050Possible to bypass timer in timed assignmentsCVE-2025-62401MDL-75087moodle.org
SeriousMSA-25-0042Upgrade FPDI including security fix (upstream)CVE-2025-54869MDL-86353moodle.org
MinorMSA-25-0034CSRF risk in badges backpack managementCVE-2025-49516MDL-84497moodle.org
SeriousMSA-25-0033Course visibility not honoured consistentlyCVE-2025-49515MDL-84518moodle.org
SeriousMSA-25-0032SSRF risk via DNS rebindCVE-2025-49514MDL-83762moodle.org
SeriousMSA-25-0031Upgrade ADOdb including security fix (upstream)CVE-2025-46337MDL-85375moodle.org
MinorMSA-25-0028IDOR when accessing the cohorts reportCVE-2025-3647MDL-84865moodle.org
SeriousMSA-25-0025Reflected XSS risk in policy toolCVE-2025-3643MDL-85104moodle.org
SeriousMSA-25-0005Stored XSS risk in admin live logCVE-2025-26529MDL-84145moodle.org
MinorMSA-25-0004Stored XSS in ddimageortext question typeCVE-2025-26528MDL-82896moodle.org
SeriousMSA-25-0001Arbitrary file read risk through pdfTeXCVE-2025-26525MDL-84136moodle.org
MinorMSA-24-0050IDOR when fetching report schedulesCVE-2024-48901MDL-83180moodle.org
MinorMSA-24-0047Some users can delete audiences of other reportsCVE-2024-48898MDL-83181moodle.org
MinorMSA-24-0046IDOR in edit/delete RSS feedCVE-2024-48897MDL-82386moodle.org
MinorMSA-24-0045Users' names returned in messaging error messageCVE-2024-48896MDL-83352moodle.org
MinorMSA-24-0043IDOR when deleting OAuth2 linked accountsCVE-2024-45690MDL-76962moodle.org
SeriousMSA-24-0040Reflected XSS via H5P error messageCVE-2024-43439MDL-82558moodle.org
SeriousMSA-24-0037Site administration SQL injection via XMLDB editorCVE-2024-43436MDL-82395moodle.org
MinorMSA-24-0036Can create global glossary without being adminCVE-2024-43435MDL-64984moodle.org
SeriousMSA-24-0035CSRF risk in Feedback non-respondents reportCVE-2024-43434MDL-82262moodle.org
SeriousMSA-24-0032IDOR in badges allows deletion of arbitrary badgesCVE-2024-43431MDL-82390moodle.org
SeriousMSA-24-0029Cache poisoning via injection into storageCVE-2024-43428MDL-81718moodle.org
SeriousMSA-24-0027Arbitrary file read risk through pdfTeXCVE-2024-43426MDL-82745moodle.org
SeriousMSA-24-0026Remote code execution via calculated question typesCVE-2024-43425MDL-82576moodle.org
SeriousMSA-24-0024CSRF risks due to misuse of confirm_sesskeyCVE-2024-38276MDL-81890moodle.org
MinorMSA-24-0019CSRF risk in analytics management of modelsCVE-2024-34008MDL-81059moodle.org
MinorMSA-24-0006IDOR on dashboard comments blockCVE-2024-25983MDL-78300moodle.org
MinorMSA-24-0005CSRF risk in Language import utilityCVE-2024-25982MDL-54749moodle.org
MinorMSA-23-0051Badge recipients are available to all usersCVE-2023-6668MDL-80268moodle.org
MinorMSA-23-0050Survey responses did not respect group settingsCVE-2023-6667MDL-79980moodle.org
SeriousMSA-23-0045DOS risk in URL downloaderCVE-2023-6662MDL-79759moodle.org
MinorMSA-23-0033XSS risk when using CSV grade import methodCVE-2023-5541MDL-79426moodle.org
SeriousMSA-23-0032Authenticated remote code execution risk in IMSCPCVE-2023-5540MDL-79409moodle.org
SeriousMSA-23-0031Authenticated remote code execution risk in LessonCVE-2023-5539MDL-79408moodle.org
MinorMSA-23-0030Quiz sequential navigation bypass possibleCVE-2023-40325MDL-71728moodle.org
MinorMSA-23-0027JQuery UI library upgraded to 1.13.2 (upstream)CVE-2022-31160, CVE-2021-41184, CVE-2021-41183, CVE-2021-41182MDL-74544moodle.org
SeriousMSA-23-0025phpCAS library upgraded to 1.6.0 (upstream)CVE-2022-39369MDL-78620moodle.org
SeriousMSA-23-0019Proxy bypass risk due to insufficient validationCVE-2023-40316MDL-74289moodle.org
MinorMSA-23-0007Algebra filter XSS when filter is misconfiguredCVE-2023-28332MDL-77524moodle.org
SeriousMSA-23-0004Authenticated SQL injection via availability checkCVE-2023-28329MDL-77046moodle.org
SeriousMSA-23-0001Reflected XSS risk in some returnurl parametersCVE-2023-23921MDL-76810moodle.org
SeriousMSA-22-0032Blind SSRF risk in LTI provider libraryCVE-2022-45152MDL-71920moodle.org
SeriousMSA-22-0030Reflected XSS risk in policy toolCVE-2022-45150MDL-76091moodle.org
MinorMSA-22-0025Minor SQL injection risk in admin user browsingCVE-2022-40315MDL-75283moodle.org
SeriousMSA-22-0021Upgrade Mustache to latest version (upstream)CVE-2022-0323MDL-75388moodle.org
MinorMSA-22-0018Open redirect risk in mobile auto-login featureCVE-2022-35652MDL-72171moodle.org
SeriousMSA-22-0016Arbitrary file read when importing lesson questionsCVE-2022-35650MDL-72029moodle.org
SeriousMSA-22-0014Failed login attempts counted incorrectlyCVE-2022-30600MDL-73736moodle.org
SeriousMSA-22-0013SQL injection risk in badge award criteriaCVE-2022-30599MDL-74333moodle.org
SeriousMSA-22-0005SQL injection risk in Badges criteria codeCVE-2022-0983MDL-74074moodle.org
SeriousMSA-22-0004CSRF risk in badge alignment deletionCVE-2022-0335MDL-72367moodle.org
SeriousMSA-21-0041CSRF risk on delete related badge featureCVE-2021-43559MDL-72370moodle.org
SeriousMSA-21-0040Reflected XSS in filetype admin toolCVE-2021-43558MDL-72571moodle.org
SeriousMSA-21-0036Quiz unreleased grade disclosure via web serviceCVE-2021-40695MDL-71797moodle.org
SeriousMSA-21-0021SQL injection risk in code fetching recent coursesCVE-2021-36393MDL-71242moodle.org
SeriousMSA-21-0013Quiz unreleased grade disclosure via web serviceCVE-2021-32473MDL-70720moodle.org
SeriousMSA-21-0006Stored XSS via ID number user profile fieldCVE-2021-20279MDL-65552moodle.org
SeriousMSA-21-0004Stored XSS possible via TeX notation filterCVE-2021-20186MDL-69911moodle.org
SeriousMSA-20-0012Reflected XSS in tag managerCVE-2020-25628MDL-69340moodle.org
SeriousMSA-20-0010yui_combo should mitigate denial of service riskCVE-2020-14322MDL-68426moodle.org
SeriousMSA-20-0006Remote code execution possible via SCORM packagesCVE-2020-10738MDL-68410moodle.org
SeriousMSA-20-0003IP addresses can be spoofed using X-Forwarded-ForCVE-2020-1755MDL-67861moodle.org
MinorMSA-19-0027Open redirect in Lesson edit pageCVE-2019-14882MDL-66228moodle.org
Moodle core is one half of the picture
Third-party plugins run with the same privileges as core and never appear in these advisories. MDL Shield reviews plugin code for exactly that gap.

Advisory titles and descriptions are Moodle's own words, from the security announcements on moodle.org, and every entry links to its source. This list is a lower bound: Moodle stops issuing advisories for a branch once it leaves security support. MDL Shield is an independent service and is not affiliated with or endorsed by Moodle Pty Ltd.