Moodle Tags Exposure in Tag Search and Block Functionality
CVE-2025-26527
5.3MEDIUM
What is CVE-2025-26527?
An issue exists in Moodle where tags that are intended to remain hidden from users can be unintentionally accessed through the tag search feature and the tags block. This exposure could result in users discovering information that should not be publicly visible, which raises concerns about data privacy and application security.
Affected Version(s)
moodle 4.5.0 < 4.5.2
moodle 4.4.0 < 4.4.6
moodle 4.3.0 < 4.3.10