CVE-2025-26525
- EPSS 0.13%
- Published 24.02.2025 20:15:33
- Last modified 08.08.2025 19:41:25
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).
CVE-2025-26526
- EPSS 0.11%
- Published 24.02.2025 20:15:33
- Last modified 08.08.2025 19:40:46
Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.
CVE-2025-26527
- EPSS 0.11%
- Published 24.02.2025 20:15:33
- Last modified 08.08.2025 19:40:08
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
CVE-2025-26528
- EPSS 0.11%
- Published 24.02.2025 20:15:33
- Last modified 08.08.2025 19:38:31
The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
CVE-2025-26529
- EPSS 0.04%
- Published 24.02.2025 20:15:33
- Last modified 08.08.2025 19:37:24
Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.
CVE-2025-26530
- EPSS 0.13%
- Published 24.02.2025 20:15:33
- Last modified 11.08.2025 14:55:22
The question bank filter required additional sanitizing to prevent a reflected XSS risk.
CVE-2025-26531
- EPSS 0.08%
- Published 24.02.2025 20:15:33
- Last modified 07.08.2025 00:06:02
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
CVE-2024-45689
- EPSS 0.2%
- Published 20.11.2024 11:15:05
- Last modified 02.06.2025 15:33:57
A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
CVE-2024-45690
- EPSS 0.22%
- Published 20.11.2024 11:15:05
- Last modified 02.06.2025 15:34:48
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
CVE-2024-45691
- EPSS 0.09%
- Published 20.11.2024 11:15:05
- Last modified 02.06.2025 15:35:23
A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic ha...