CVE-2022-40314: Moodle
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
Affected products
- Moodle Moodle: from 3.9, before 3.9.17 (fixed in 3.9.17); from 3.11, before 3.11.10 (fixed in 3.11.10); from 4.0, before 4.0.4 (fixed in 4.0.4)
Published 2022-09-30. Last modified 2026-06-17.