MDL Shield
Version checkMoodle 4.1.21

Moodle 4.1.21 4.1 no longer receives security fixesLTS

Released 6 Oct 2025. Moodle 4.1 had its last security release, 4.1.22, on 8 Dec 2025, and its security support ended 8 Dec 2025. Advisories published since then list it only as an earlier unsupported version.

46 security advisories since 4.1.21

36 of them were published after 4.1 left security support, so no 4.1 release fixes them. The fix is a major upgrade: 4.5.14 is the current long-term support release, 5.2.3 the newest.

46
Advisories
23
Serious
23
Minor
36
Not fixed in 4.1
10
CVE pending
Group by
46 advisories, newest first
Serious23

The XML grade import functionality (which allows setting or overwriting of student grades) did not include the necessary token to prevent a CSRF risk.

CVE pendingMDL-84545Not fixed on 4.19 Sep 2026moodle.org

User profile descriptions for authenticated users posed a denial of service risk due to the absence of a defined maximum length.

CVE-2026-58347MDL-87898Not fixed on 4.122 Jun 2026moodle.org

The grade item ID number editing functionality did not include the necessary token to prevent a CSRF risk and also lacked sufficient output sanitizing to prevent an XSS risk.

CVE-2026-58340MDL-88542Not fixed on 4.122 Jun 2026moodle.org

Additional checks were required to ensure users with the capability to delete comments can only do so in the contexts where they have the permission.

CVE-2026-58336MDL-88619Not fixed on 4.122 Jun 2026moodle.org

A remote code execution risk was identified in the admin presets import feature. Note: This feature is only available to site administrators.

CVE-2026-58334MDL-88735Not fixed on 4.122 Jun 2026moodle.org
SeriousMSA-26-0013Email-based MFA bypass

A flaw in email-based multi-factor authentication made it possible for a user to bypass another user's MFA token check if using the email factor. Note: Valid login credentials (such as username and password) were still required to log into the account.

CVE-2026-58332MDL-88767Not fixed on 4.122 Jun 2026moodle.org
Minor23

Insufficient username escaping could allow a minor XSS risk if an unauthenticated user was tricked into opening a password reset link (so did not affect authenticated user sessions).

CVE pendingMDL-88335Not fixed on 4.19 Sep 2026moodle.org

The report builder fragment output callbacks did not verify that the requesting user had the required capability to access the requested report, potentially allowing users to retrieve report data beyond their permitted access.

CVE-2026-58348MDL-84535Not fixed on 4.122 Jun 2026moodle.org

A blind SSRF risk was identified in the MNet peers management functionality, due to missing validation of peer hostnames against the cURL blocked hosts configuration. Note: This feature is only available to site administrators.

CVE-2026-58346MDL-87911Not fixed on 4.122 Jun 2026moodle.org

Capability checks were missing from course assistance AI placement web services, which could allow users to make requests to those AI course assistance web services without having the relevant capabilities (if those features are enabled).

CVE-2026-58343MDL-88533Not fixed on 4.122 Jun 2026moodle.org

Missing group access checks in some grade web services could allow a user to access grade and user information for students in groups they did not have permission to view.

CVE-2026-58335MDL-88667Not fixed on 4.122 Jun 2026moodle.org
You are here: Moodle 4.1.21
Released 6 Oct 2025. Each release below closes the advisories listed under it.
Moodle 4.1.228 Dec 2025 · 10 advisoriesLast release5 Serious5 Minor
No 4.1 releasePublished after 8 Dec 2025, when 4.1 left security support · 36 advisories18 Serious18 Minor
SeriousMSA-26-0041CSRF risk in XML grade importsCVE pendingMDL-84545moodle.org
MinorMSA-26-0039Minor XSS risk via password reset linkCVE pendingMDL-88335moodle.org
MinorMSA-26-0034XSS risk in forum post templatesCVE pendingMDL-88981moodle.org
SeriousMSA-26-0031SQL injection risk in question bank web serviceCVE pendingMDL-89383moodle.org
SeriousMSA-26-0028DoS risk via user profile descriptionCVE-2026-58347MDL-87898moodle.org
MinorMSA-26-0027Blind SSRF risk in MNet peers functionCVE-2026-58346MDL-87911moodle.org
SeriousMSA-26-0025CSRF risk in quiz attempt regradingCVE-2026-58344MDL-88531moodle.org
MinorMSA-26-0023CSRF risk when adding quiz section headingsCVE-2026-58342MDL-88540moodle.org
MinorMSA-26-0022CSRF risk in group messaging state toggleCVE-2026-58341MDL-88541moodle.org
SeriousMSA-26-0021CSRF and XSS in grade item idnumber editingCVE-2026-58340MDL-88542moodle.org
MinorMSA-26-0020Reflected XSS via Feedback import error messageCVE-2026-58339MDL-88543moodle.org
MinorMSA-26-0019CSRF risk in user profile page resetCVE-2026-58338MDL-88545moodle.org
MinorMSA-26-0018CSRF risk in user homepage preference settingCVE-2026-58337MDL-88609moodle.org
SeriousMSA-26-0017IDOR allows arbitrary comment deletionCVE-2026-58336MDL-88619moodle.org
SeriousMSA-26-0015RCE risk via admin presets importCVE-2026-58334MDL-88735moodle.org
SeriousMSA-26-0014Arbitrary file read risk in backup restoreCVE-2026-58333MDL-88736moodle.org
SeriousMSA-26-0013Email-based MFA bypassCVE-2026-58332MDL-88767moodle.org
SeriousMSA-26-0003Denial of service risk in TeX formula editorCVE-2026-26047MDL-86785moodle.org
SeriousMSA-26-0001Remote code execution risk via file restoreCVE-2026-26045MDL-87612moodle.org
Moodle core is one half of the picture
Third-party plugins run with the same privileges as core and never appear in these advisories. MDL Shield reviews plugin code for exactly that gap.

Advisory titles and descriptions are Moodle's own words, from the security announcements on moodle.org, and every entry links to its source. This list is a lower bound: Moodle stops issuing advisories for a branch once it leaves security support. MDL Shield is an independent service and is not affiliated with or endorsed by Moodle Pty Ltd.