MDL Shield
Version checkMoodle 4.5.11

Moodle 4.5.11 4.5 is supportedLTS

Released 20 Apr 2026. The current 4.5 release is 4.5.14, published 14 Sep 2026.

27 security advisories since 4.5.11

Every one of them is fixed in 4.5.14, the current 4.5 release, 3 releases ahead of you. Upgrading within the branch is a minor update with no feature changes.

27
Advisories
12
Serious
15
Minor
0
Not fixed in 4.5
10
CVE pending
Group by
27 advisories, newest first
Serious12

The XML grade import functionality (which allows setting or overwriting of student grades) did not include the necessary token to prevent a CSRF risk.

CVE pendingMDL-84545Fixed in 4.5.139 Sep 2026moodle.org

User profile descriptions for authenticated users posed a denial of service risk due to the absence of a defined maximum length.

CVE-2026-58347MDL-87898Fixed in 4.5.1222 Jun 2026moodle.org

The grade item ID number editing functionality did not include the necessary token to prevent a CSRF risk and also lacked sufficient output sanitizing to prevent an XSS risk.

CVE-2026-58340MDL-88542Fixed in 4.5.1222 Jun 2026moodle.org

A remote code execution risk was identified in the admin presets import feature. Note: This feature is only available to site administrators.

CVE-2026-58334MDL-88735Fixed in 4.5.1222 Jun 2026moodle.org
SeriousMSA-26-0013Email-based MFA bypass

A flaw in email-based multi-factor authentication made it possible for a user to bypass another user's MFA token check if using the email factor. Note: Valid login credentials (such as username and password) were still required to log into the account.

CVE-2026-58332MDL-88767Fixed in 4.5.1222 Jun 2026moodle.org
Minor15

Insufficient username escaping could allow a minor XSS risk if an unauthenticated user was tricked into opening a password reset link (so did not affect authenticated user sessions).

CVE pendingMDL-88335Fixed in 4.5.139 Sep 2026moodle.org

The report builder fragment output callbacks did not verify that the requesting user had the required capability to access the requested report, potentially allowing users to retrieve report data beyond their permitted access.

CVE-2026-58348MDL-84535Fixed in 4.5.1222 Jun 2026moodle.org

A blind SSRF risk was identified in the MNet peers management functionality, due to missing validation of peer hostnames against the cURL blocked hosts configuration. Note: This feature is only available to site administrators.

CVE-2026-58346MDL-87911Fixed in 4.5.1222 Jun 2026moodle.org

Capability checks were missing from course assistance AI placement web services, which could allow users to make requests to those AI course assistance web services without having the relevant capabilities (if those features are enabled).

CVE-2026-58343MDL-88533Fixed in 4.5.1222 Jun 2026moodle.org

Missing group access checks in some grade web services could allow a user to access grade and user information for students in groups they did not have permission to view.

CVE-2026-58335MDL-88667Fixed in 4.5.1222 Jun 2026moodle.org
You are here: Moodle 4.5.11
Released 20 Apr 2026. Each release below closes the advisories listed under it.
Moodle 4.5.128 Jun 2026 · 17 advisories8 Serious9 Minor
SeriousMSA-26-0028DoS risk via user profile descriptionCVE-2026-58347MDL-87898moodle.org
MinorMSA-26-0027Blind SSRF risk in MNet peers functionCVE-2026-58346MDL-87911moodle.org
SeriousMSA-26-0025CSRF risk in quiz attempt regradingCVE-2026-58344MDL-88531moodle.org
MinorMSA-26-0023CSRF risk when adding quiz section headingsCVE-2026-58342MDL-88540moodle.org
MinorMSA-26-0022CSRF risk in group messaging state toggleCVE-2026-58341MDL-88541moodle.org
SeriousMSA-26-0021CSRF and XSS in grade item idnumber editingCVE-2026-58340MDL-88542moodle.org
MinorMSA-26-0020Reflected XSS via Feedback import error messageCVE-2026-58339MDL-88543moodle.org
MinorMSA-26-0019CSRF risk in user profile page resetCVE-2026-58338MDL-88545moodle.org
MinorMSA-26-0018CSRF risk in user homepage preference settingCVE-2026-58337MDL-88609moodle.org
SeriousMSA-26-0015RCE risk via admin presets importCVE-2026-58334MDL-88735moodle.org
SeriousMSA-26-0014Arbitrary file read risk in backup restoreCVE-2026-58333MDL-88736moodle.org
SeriousMSA-26-0013Email-based MFA bypassCVE-2026-58332MDL-88767moodle.org
Moodle 4.5.1310 Aug 2026 · 10 advisories4 Serious6 Minor
Moodle 4.5.1414 Sep 2026 · No advisories publishedCurrent release
Moodle core is one half of the picture
Third-party plugins run with the same privileges as core and never appear in these advisories. MDL Shield reviews plugin code for exactly that gap.

Advisory titles and descriptions are Moodle's own words, from the security announcements on moodle.org, and every entry links to its source. This list is a lower bound: Moodle stops issuing advisories for a branch once it leaves security support. MDL Shield is an independent service and is not affiliated with or endorsed by Moodle Pty Ltd.