CVE-2025-26525: Moodle
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).
Affected products
- Moodle Moodle: from 4.1.0, before 4.1.16 (fixed in 4.1.16); from 4.3.0, before 4.3.10 (fixed in 4.3.10); from 4.4.0, before 4.4.6 (fixed in 4.4.6); from 4.5.0, before 4.5.2 (fixed in 4.5.2)
Published 2025-02-24. Last modified 2026-06-17.