The XML grade import functionality (which allows setting or overwriting of student grades) did not include the necessary token to prevent a CSRF risk.
Moodle 5.1.2 5.1 is supported
Released 9 Feb 2026. The current 5.1 release is 5.1.7, published 14 Sep 2026.
Every one of them is fixed in 5.1.7, the current 5.1 release, 5 releases ahead of you. Upgrading within the branch is a minor update with no feature changes.
An incorrect capability check in a grade web service allowed students to access profile information of other students enrolled in the same course, which they would not otherwise have access to.
An SQL injection risk was identified in a question bank web service.
Incorrect handling of IPv4-mapped IPv6 addresses could allow bypassing of some blocked hosts, resulting in an SSRF risk.
User profile descriptions for authenticated users posed a denial of service risk due to the absence of a defined maximum length.
Insufficient capability checks in the Assignment module's marker allocation functionality allowed users without the required capability to allocate markers to submissions.
The regrade action in the quiz overview report did not include the necessary token to prevent a CSRF risk.
The grade item ID number editing functionality did not include the necessary token to prevent a CSRF risk and also lacked sufficient output sanitizing to prevent an XSS risk.
Additional checks were required to ensure users with the capability to delete comments can only do so in the contexts where they have the permission.
A remote code execution risk was identified in the admin presets import feature. Note: This feature is only available to site administrators.
An arbitrary file read risk was identified in the backup restore functionality.
A flaw in email-based multi-factor authentication made it possible for a user to bypass another user's MFA token check if using the email factor. Note: Valid login credentials (such as username and password) were still required to log into the account.
An arbitrary file read risk was identified in the Database Activity module's import feature.
A remote code execution risk was identified in Moodle's Google Drive repository plugin.
An SQL injection risk was identified in the "external database" authentication plugin (auth_db). Note: This only affected sites with the auth_db authentication plugin enabled.
User list filters allowed managers to filter by user profile fields that they could not view on users' profiles.
Insufficient username escaping could allow a minor XSS risk if an unauthenticated user was tricked into opening a password reset link (so did not affect authenticated user sessions).
A check to validate a group belonged to a course was missing, which made it possible for teachers to add users to groups in courses that the teacher could not otherwise access.
Missing capability checks made it possible for users to trigger grade penalty recalculation without having the capability to do so.
An incorrect capability check in the AI "generate image" web service could allow users to access that feature without having the "generate image" capability.
The manual enrolment management page did not prevent direct access when the plugin was disabled and a link was no longer available in the UI. Note: This still required the relevant capability to access the page (had it been enabled).
Insufficient escaping resulted in an XSS risk in some templates used to display forum posts.
Insufficient validation of the audience classname in report builder allowed arbitrary class instantiation.
The report builder fragment output callbacks did not verify that the requesting user had the required capability to access the requested report, potentially allowing users to retrieve report data beyond their permitted access.
A blind SSRF risk was identified in the MNet peers management functionality, due to missing validation of peer hostnames against the cURL blocked hosts configuration. Note: This feature is only available to site administrators.
Capability checks were missing from course assistance AI placement web services, which could allow users to make requests to those AI course assistance web services without having the relevant capabilities (if those features are enabled).
The quiz feature to add section headings did not include the necessary token to prevent a CSRF risk.
The actions to enable and disable group messaging did not include the necessary token to prevent a CSRF risk.
The Feedback activity module's import functionality required additional sanitizing to prevent a reflected XSS risk.
The user profile page reset action did not include the necessary token to prevent a CSRF risk.
The setting for users to set their own homepage preference did not include the necessary token to prevent a CSRF risk.
Missing group access checks in some grade web services could allow a user to access grade and user information for students in groups they did not have permission to view.
Insufficient CSRF token and capability checks were applied to an MNet admin setting.
The upstream AWS SDK for PHP library was upgraded, which included a security fix.
The grade penalty rules reset function did not include the necessary token to prevent a CSRF risk.
A flaw in message handling of conversations with deleted users could result in active users losing access to their private messages.
Advisory titles and descriptions are Moodle's own words, from the security announcements on moodle.org, and every entry links to its source. This list is a lower bound: Moodle stops issuing advisories for a branch once it leaves security support. MDL Shield is an independent service and is not affiliated with or endorsed by Moodle Pty Ltd.