MDL Shield
Version checkMoodle 4.5.3

Moodle 4.5.3 4.5 is supportedLTS

Released 17 Mar 2025. The current 4.5 release is 4.5.14, published 14 Sep 2026.

83 security advisories since 4.5.3

Every one of them is fixed in 4.5.14, the current 4.5 release, 11 releases ahead of you. Upgrading within the branch is a minor update with no feature changes.

83
Advisories
36
Serious
47
Minor
0
Not fixed in 4.5
10
CVE pending
Group by
83 advisories, newest first
Serious36

The XML grade import functionality (which allows setting or overwriting of student grades) did not include the necessary token to prevent a CSRF risk.

CVE pendingMDL-84545Fixed in 4.5.139 Sep 2026moodle.org

User profile descriptions for authenticated users posed a denial of service risk due to the absence of a defined maximum length.

CVE-2026-58347MDL-87898Fixed in 4.5.1222 Jun 2026moodle.org

The grade item ID number editing functionality did not include the necessary token to prevent a CSRF risk and also lacked sufficient output sanitizing to prevent an XSS risk.

CVE-2026-58340MDL-88542Fixed in 4.5.1222 Jun 2026moodle.org

Additional checks were required to ensure users with the capability to delete comments can only do so in the contexts where they have the permission.

CVE-2026-58336MDL-88619Fixed in 4.5.1222 Jun 2026moodle.org

A remote code execution risk was identified in the admin presets import feature. Note: This feature is only available to site administrators.

CVE-2026-58334MDL-88735Fixed in 4.5.1222 Jun 2026moodle.org
SeriousMSA-26-0013Email-based MFA bypass

A flaw in email-based multi-factor authentication made it possible for a user to bypass another user's MFA token check if using the email factor. Note: Valid login credentials (such as username and password) were still required to log into the account.

CVE-2026-58332MDL-88767Fixed in 4.5.1222 Jun 2026moodle.org
SeriousMSA-25-0047Possible to bypass MFA

Incorrect handling of some endpoints during login made it possible to bypass the second factor of multi-factor authentication. Note: A valid username and password were still required to log in.

CVE-2025-62398MDL-86334Fixed in 4.5.714 Oct 2025moodle.org

Insufficient state and capability checks resulted in some details of hidden courses (such as course name, description and teachers) being available to users who did not have permission to access them.

CVE-2025-49515MDL-84518Fixed in 4.5.517 Jun 2025moodle.org
SeriousMSA-25-0032SSRF risk via DNS rebind

A DNS rebind risk in the way cURL requests were handled could result in an SSRF risk, due to the possibility of cURL blocked hosts / allowed ports site configurations being bypassed.

CVE-2025-49514MDL-83762Fixed in 4.5.517 Jun 2025moodle.org

The upstream ADOdb library contained an SQL injection risk in the pg_insert_id() method. It is important to note that the core Moodle LMS was NOT affected by this vulnerability, however as a precaution, this library has been upgraded to remove the risk entirely, in case any third party code/plugins uses the vulnerable code.

CVE-2025-46337MDL-85375Fixed in 4.5.517 Jun 2025moodle.org
Minor47

Insufficient username escaping could allow a minor XSS risk if an unauthenticated user was tricked into opening a password reset link (so did not affect authenticated user sessions).

CVE pendingMDL-88335Fixed in 4.5.139 Sep 2026moodle.org

The report builder fragment output callbacks did not verify that the requesting user had the required capability to access the requested report, potentially allowing users to retrieve report data beyond their permitted access.

CVE-2026-58348MDL-84535Fixed in 4.5.1222 Jun 2026moodle.org

A blind SSRF risk was identified in the MNet peers management functionality, due to missing validation of peer hostnames against the cURL blocked hosts configuration. Note: This feature is only available to site administrators.

CVE-2026-58346MDL-87911Fixed in 4.5.1222 Jun 2026moodle.org

Capability checks were missing from course assistance AI placement web services, which could allow users to make requests to those AI course assistance web services without having the relevant capabilities (if those features are enabled).

CVE-2026-58343MDL-88533Fixed in 4.5.1222 Jun 2026moodle.org

Missing group access checks in some grade web services could allow a user to access grade and user information for students in groups they did not have permission to view.

CVE-2026-58335MDL-88667Fixed in 4.5.1222 Jun 2026moodle.org

Separate Groups mode restrictions were not honoured when viewing a course's Logs report, so actions of all course participants were displayed in the report. By default this only provided additional access to non-editing teachers.

CVE-2025-62436MDL-84464Fixed in 4.5.621 Aug 2025moodle.org

On sites with Multi-Factor Authentication enabled, it was possible to use course self enrolment after passing only the first login factor (such as passing a username/password check). The user should also have to pass a second login factor before gaining access to self enrolment.

CVE-2025-3634MDL-84784Fixed in 4.5.422 Apr 2025moodle.org

On sites with Multi-Factor Authentication enabled, it was possible for a user to access some of their data after passing only the first login factor (such as passing a username/password check). The user should have to also pass a second factor check before gaining access to that data.

CVE-2025-3627MDL-84351Fixed in 4.5.422 Apr 2025moodle.org
You are here: Moodle 4.5.3
Released 17 Mar 2025. Each release below closes the advisories listed under it.
Moodle 4.5.414 Apr 2025 · 16 advisories5 Serious11 Minor
MinorMSA-25-0028IDOR when accessing the cohorts reportCVE-2025-3647MDL-84865moodle.org
SeriousMSA-25-0025Reflected XSS risk in policy toolCVE-2025-3643MDL-85104moodle.org
Moodle 4.5.59 Jun 2025 · 7 advisories4 Serious3 Minor
Moodle 4.5.611 Aug 2025 · 3 advisories3 Minor
Moodle 4.5.76 Oct 2025 · 8 advisories2 Serious6 Minor
Moodle 4.5.88 Dec 2025 · 11 advisories6 Serious5 Minor
SeriousMSA-25-0059Reflected XSS risk in policy toolCVE-2025-67855MDL-86544moodle.org
MinorMSA-25-0056Open redirect in OAuth loginCVE-2025-67852MDL-80317moodle.org
SeriousMSA-25-0054XSS risk in formula editorCVE-2025-67850MDL-85557moodle.org
SeriousMSA-25-0053XSS risk via AI prompt injectionCVE-2025-67849MDL-87267moodle.org
SeriousMSA-25-0051Remote code execution risk via file restoreCVE-2025-67847MDL-87353moodle.org
Moodle 4.5.99 Feb 2026 · 4 advisories4 Serious
Moodle 4.5.1011 Feb 2026 · No advisories published
Moodle 4.5.1120 Apr 2026 · 6 advisories2 Serious4 Minor
Moodle 4.5.128 Jun 2026 · 18 advisories9 Serious9 Minor
SeriousMSA-26-0028DoS risk via user profile descriptionCVE-2026-58347MDL-87898moodle.org
MinorMSA-26-0027Blind SSRF risk in MNet peers functionCVE-2026-58346MDL-87911moodle.org
SeriousMSA-26-0025CSRF risk in quiz attempt regradingCVE-2026-58344MDL-88531moodle.org
MinorMSA-26-0023CSRF risk when adding quiz section headingsCVE-2026-58342MDL-88540moodle.org
MinorMSA-26-0022CSRF risk in group messaging state toggleCVE-2026-58341MDL-88541moodle.org
SeriousMSA-26-0021CSRF and XSS in grade item idnumber editingCVE-2026-58340MDL-88542moodle.org
MinorMSA-26-0020Reflected XSS via Feedback import error messageCVE-2026-58339MDL-88543moodle.org
MinorMSA-26-0019CSRF risk in user profile page resetCVE-2026-58338MDL-88545moodle.org
MinorMSA-26-0018CSRF risk in user homepage preference settingCVE-2026-58337MDL-88609moodle.org
SeriousMSA-26-0017IDOR allows arbitrary comment deletionCVE-2026-58336MDL-88619moodle.org
SeriousMSA-26-0015RCE risk via admin presets importCVE-2026-58334MDL-88735moodle.org
SeriousMSA-26-0014Arbitrary file read risk in backup restoreCVE-2026-58333MDL-88736moodle.org
SeriousMSA-26-0013Email-based MFA bypassCVE-2026-58332MDL-88767moodle.org
Moodle 4.5.1310 Aug 2026 · 10 advisories4 Serious6 Minor
Moodle 4.5.1414 Sep 2026 · No advisories publishedCurrent release
Moodle core is one half of the picture
Third-party plugins run with the same privileges as core and never appear in these advisories. MDL Shield reviews plugin code for exactly that gap.

Advisory titles and descriptions are Moodle's own words, from the security announcements on moodle.org, and every entry links to its source. This list is a lower bound: Moodle stops issuing advisories for a branch once it leaves security support. MDL Shield is an independent service and is not affiliated with or endorsed by Moodle Pty Ltd.