CWE-425
CWE-425 · 3 records · 0 with a public proof-of-concept
Records the NVD classes under CWE-425, highest CVSS first.
- MEDIUM 4.3CVE-2026-102584
A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to modify grade penalty records, …
- LOW 2.7CVE-2026-102583
A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthor…
- LOW 2.2CVE-2026-102582
A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorize…