Moodle Arbitrary Code Execution Vulnerability via Restore Interface

Vulnerability

A code execution vulnerability has been identified in Moodle. This issue arises from inadequate validation of input in the restore interface, allowing an attacker to execute arbitrary code on the server side. The flaw could lead to a complete compromise of the Moodle application.

Impact

Exploitation of this vulnerability allows for server-side execution of arbitrary code, potentially leading to a full compromise of the Moodle application.

Added: Jan 23, 2026, 5:19 AM
Updated: Jan 23, 2026, 5:19 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
10.0
exploitability
5.2
remediation
0.0
relevance
2.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.