OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2025-63564

CRITICAL · CVSS 9.8 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Moodle Socialwall plugin versions 3.0 to 3.3 are vulnerable to an SQL injection flaw that enables attackers to execute arbitrary code through specially crafted HTTP requests. This vulnerability poses a significant risk to the integrity and confidentiality of data within affected Moodle installations. Organizations using these versions of the plugin should prioritize patching or upgrading to mitigate potential exploitation.

CVE
CVE-2025-63564
Severity
CRITICAL
CVSS
9.8
EPSS
0.51%

Original NVD Description

SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests