CVE-2016-5014: Moodle

Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.

In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.

Affected products

  • Moodle Moodle: version 2.8.0 only; version 2.8.1 only; version 2.8.2 only; version 2.8.3 only; version 2.8.4 only; version 2.8.5 only; …

Published 2017-01-20. Last modified 2026-06-17.