Back to Database
Status published
Medium
CVE-2025-26526
Feedback response viewing and deletions did not respect Separate Groups mode
Vulnerability Description
Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-26526
Credits & Attribution
No credits recorded in the NVD database.
References
More from Moodle Project
View All →CVE-2025-26533
SQL injection risk in course search module list filter
High
8.1
CVE-2025-26532
Teachers can evade trusttext config when restoring glossary entries
Low
3.1
CVE-2025-26531
IDOR in badges allows disabling of arbitrary badges
Low
3.1
CVE-2025-26530
Reflected XSS via question bank filter
High
8.3
CVE-2025-26529
Stored XSS risk in admin live log
High
8.3
Affected Vendor
Moodle Project
View all reports →Affected Software
moodle
Vulnerable Versions:
4.5.0, 4.4.0, 4.3.0, 4.1.0, 4.2.0, 0
Timeline
Official Publish:
February 24th, 2025
Last Modified:
February 24th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N