CVE-2025-26532: Teachers can evade trusttext config when restoring glossary entries
Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.1.16 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.3.10 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.4.6 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.5.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26532?
The severity of CVE-2025-26532 is currently rated as medium, indicating a moderate risk to affected systems.
How do I fix CVE-2025-26532?
To fix CVE-2025-26532, ensure that you update Moodle to versions 4.1.16, 4.3.10, 4.4.6, or 4.5.2 or later.
What software is affected by CVE-2025-26532?
CVE-2025-26532 affects Moodle versions up to 4.1.16 and select versions from 4.3.0-beta to 4.5.0-beta.
What does CVE-2025-26532 involve?
CVE-2025-26532 involves inadequate checks for applying trusttext to glossary entries upon restoration when enabled.
Is CVE-2025-26532 being actively exploited?
There is currently no public information indicating that CVE-2025-26532 is being actively exploited in the wild.