Skip to main content

Moodle 5.0.9

Unsupported Moodle Version
This version of Moodle is no longer supported for general bug fixes.
You are encouraged to upgrade to a supported version of Moodle.

Release date: 10 August 2026

Here is the full list of fixed issues in 5.0.9.

General fixes and improvements

  • MDL-88878 - OpenAI AI provider: json_encode() escapes slashes in model name, causing 404 with OpenAI-compatible providers
  • MDL-89307 - AI provider action settings page sets a wrong page URL, breaking any redirects (ie "Edit mode" button)

Security fixes

  • MSA-26-0030 - SSRF risk in URL downloader (bypass some blocked hosts)
  • MSA-26-0031 - SQL injection risk in question bank web service
  • MSA-26-0032 - User profile information disclosure via grade web service
  • MSA-26-0033 - Arbitrary class instantiation via audience classname in core_reportbuilder
  • MSA-26-0034 - XSS risk in forum post templates
  • MSA-26-0035 - Manual enrolment does not correctly observe disabled state of plugin
  • MSA-26-0036 - Incorrect capability check in AI editor placement "generate image" service
  • MSA-26-0037 - Missing capability checks allow unauthorised triggering of grade penalty recalculation
  • MSA-26-0039 - Minor XSS risk via password reset link
  • MSA-26-0040 - User list filters do not respect user profile field visibility
  • MSA-26-0041 - CSRF risk in XML grade imports