Vulnerability record · CVE-2025-67851 · published 3 February 2026
CVE-2025-67851: Moodle csv injection vulnerability
Moodle · Moodle
A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.
Description
A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2025-67851 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2423841 | Issue TrackingThird Party Advisory |
| https://moodle.org/mod/forum/discuss.php?d=471301 | Vendor Advisory |
Track CVE-2025-67851 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-67851), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.