CVE-2025-67857: Moodle

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.

Affected products

  • Moodle Moodle: before 4.1.21 (fixed in 4.1.21); from 4.4.0, before 4.4.11 (fixed in 4.4.11); from 4.5.0, before 4.5.8 (fixed in 4.5.8); from 5.0.0, before 5.0.4 (fixed in 5.0.4); version 5.1.0 only

Published 2026-02-03. Last modified 2026-06-17.