Security: mdjnelson/moodle-mod_customcert
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Authorization bypass in save_element() via mutation of server-controlled element identity fieldsGHSA-4xmv-rv36-86m8 published
Sep 19, 2026 by mdjnelsonModerate -
Unauthenticated certificate-issuance existence oracle in my_certificates.phpGHSA-qwq6-7rgx-6x8m published
Aug 10, 2026 by mdjnelsonLow -
view.php downloadissue lets a report-viewer generate a certificate PDF for an arbitrary user who was never issued the certificateGHSA-9wrp-7wwq-hghj published
Aug 10, 2026 by mdjnelsonModerate -
Missing capability check allows any context-authorised user to fetch element HTML and the admin edit-element form fragmentGHSA-jqvj-6wpm-mv8w published
Aug 10, 2026 by mdjnelsonLow -
Cross-course certificate template disclosure via missing source-template authorization in load_template.phpGHSA-r86f-x9v9-g8j7 published
Aug 2, 2026 by mdjnelsonModerate -
Authorization Bypass Through User-Controlled Key in mdjnelson/moodle-mod_customcertGHSA-8pjr-j7r4-ccjx published
Mar 15, 2026 by mdjnelsonCritical
Learn more about advisories related to mdjnelson/moodle-mod_customcert in the GitHub Advisory Database