# Multiples vulnérabilités dans Moodle (22 septembre 2026)

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: CERT-FR / ANSSI
- Category: Vulnerabilities
- Original publication time: 2026-09-22T00:00:00Z
- First observed by NexusTechWire: 2026-10-01T20:28:40Z
- Original source: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1210/
- NexusTechWire record: https://nexustechwire.com/news/news-b1fe6328b4f8bf88b553

## The brief

CERT-FR warns of SQL injection and security-policy bypass vulnerabilities in Moodle. Its September 22 advisory covers releases earlier than 4.5.14, plus the 5.0, 5.1 and 5.2 branches before 5.0.10, 5.1.7 and 5.2.3 respectively. It links two Moodle security notices published that day and directs site administrators to them for the corresponding fixes.

AI-assisted NexusTechWire summary, checked against the linked source on 2026-10-01T21:18:05Z. Not independent reporting.

Source license: [Etalab Open Licence v2.0](https://www.etalab.gouv.fr/wp-content/uploads/2017/04/ETALAB-Licence-Ouverte-v2.0.pdf). Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read the full original: [CERT-FR / ANSSI](https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1210/)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
