CVE-2023-35131: Moodle
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.
Affected products
- Moodle Moodle: from 3.11.0, before 3.11.15 (fixed in 3.11.15); from 4.0.0, before 4.0.9 (fixed in 4.0.9); from 4.1.0, before 4.1.4 (fixed in 4.1.4); version 4.2.0 only
Published 2023-06-22. Last modified 2026-06-17.