---
id: CVE-2025-63564
title: >-
  SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3
  allows an attacker to execute arbitrary code via crafted HTTP requests
summary: >-
  SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3
  allows an attacker to execute arbitrary code via crafted HTTP requests
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-63564'
references:
  - url: 'http://moodle.com'
    label: cve@mitre.org
  - url: 'https://medium.com/@lcrawfqrd/sqli-in-moodle-plugin-9f0ce4eb05f2'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
epss: 0.00505
epssPercentile: 0.4053
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-23T19:30:43.427357Z'
ingestedAt: '2026-09-23T16:27:22.661Z'
---

## Overview

SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
