CVE-2025-26527: Non-searchable tags can still be discovered on the tag search page and in the tags block
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.1.16 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.3.10 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.4.6 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.5.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26527?
CVE-2025-26527 is classified as a medium severity vulnerability.
How does CVE-2025-26527 affect users?
CVE-2025-26527 allows users to discover tags that are not meant to be visible through the tag search page or tags block.
How do I fix CVE-2025-26527?
To fix CVE-2025-26527, update your Moodle installation to versions 4.1.16, 4.3.10, 4.4.6, or 4.5.2.
Which versions of Moodle are affected by CVE-2025-26527?
CVE-2025-26527 affects Moodle versions before 4.1.16, 4.3.10, 4.4.6, and 4.5.2.
Is there a workaround for CVE-2025-26527?
Currently, there are no known workarounds for CVE-2025-26527 aside from upgrading to a patched version.