Skip to main content

Moodle 5.0.9

Unsupported Moodle Version
This version of Moodle is no longer supported and will not receive fixes for security risks.
You are encouraged to upgrade to a supported version of Moodle.

Release date: 10 August 2026

Here is the full list of fixed issues in 5.0.9.

General fixes and improvements​

  • MDL-88878 - OpenAI AI provider: json_encode() escapes slashes in model name, causing 404 with OpenAI-compatible providers
  • MDL-89307 - AI provider action settings page sets a wrong page URL, breaking any redirects (ie "Edit mode" button)

Security fixes​

  • MSA-26-0030 - SSRF risk in URL downloader (bypass some blocked hosts)
  • MSA-26-0031 - SQL injection risk in question bank web service
  • MSA-26-0032 - User profile information disclosure via grade web service
  • MSA-26-0033 - Arbitrary class instantiation via audience classname in core_reportbuilder
  • MSA-26-0034 - XSS risk in forum post templates
  • MSA-26-0035 - Manual enrolment does not correctly observe disabled state of plugin
  • MSA-26-0036 - Incorrect capability check in AI editor placement "generate image" service
  • MSA-26-0037 - Missing capability checks allow unauthorised triggering of grade penalty recalculation
  • MSA-26-0039 - Minor XSS risk via password reset link
  • MSA-26-0040 - User list filters do not respect user profile field visibility
  • MSA-26-0041 - CSRF risk in XML grade imports