Skip to main content

Moodle 5.0.7

Security Support Only Moodle Version
This version of Moodle receives security fixes, but is no longer supported for general bug fixes.
You may view the releases page to see the support status of all Moodle versions.

Release date: 20 April 2026

Here is the full list of fixed issues in 5.0.7.

General fixes and improvements

  • MDL-60912 - Percentage complete in course overview on Dashboard does not consider hidden or blocked activities
  • MDL-66415 - Bulk messaging results in an exception if at least one recipient rejects a message (e.g. hidden courses, suspended enrolments, no shared courses)
  • MDL-79324 - Secure quiz Back button navigation causes loss of unsaved answers without warning
  • MDL-86809 - "Receive a grade" completion condition not disabled with activity marked as done for one or more students
  • MDL-78343 - Report download (e.g. quiz responses) truncates response text after less-than sign
  • MDL-84045 - Course page editing scrolls to top instead of previous position
  • MDL-77558 - Reading forum posts in grading window does not mark them as read
  • MDL-29421 - Form elements editor does not support freezing
  • MDL-74519 - Badges are issued without satisfying course completion criteria
  • MDL-80496 - Code snippets with comments display poorly in quizzes with code highlighter enabled
  • MDL-85352 - Add support for b64_json to the generate_image action in OpenAI provider
  • MDL-86154 - Importing quizzes leads to question bank entries without a valid category
  • MDL-88092 - Update H5P library to version 1.28
  • MDL-86524 - Incorrect context and tag IDs when restoring question set references to another server
  • MDL-86112 - Students may get a "TypeError" dialog when self-completing an "available but not shown" activity
  • MDL-85544 - Glossary entries are not sorted case-insensitively
  • MDL-83437 - The sticky footer hides menus (backport of MDL-87301)
  • MDL-86866 - Return JSON for API web failures, and HTML for General web failures
  • MDL-87822 - Minor change in cURL class breaks Microsoft O365 plugin
  • MDL-85301 - Ollama AI provider doesn't work with option "Enable basic authentication"
  • MDL-88006 - AI responses need line breaks corrected
  • MDL-87592 - The MFA link a user originally requests to access when using email based self-registration is forgotten
  • MDL-86691 - Error when editing random questions for quizzes migrated from Moodle 4
  • MDL-85111 - Essay question word count corrupted by less-than sign
  • MDL-68062 - BadgeNotFound error when non-issuer revokes badge manually
  • MDL-87482 - Libxml2 >= 2.14.0 breaks messaging
  • MDL-87458 - Course reset deletes BigBlueButton recordings from server instead of removing local references only
  • MDL-88109 - Incorrect URL object handling in redirect response
  • MDL-88093 - failed_task_callbacks sends emails to admins in the wrong language
  • MDL-88080 - Admin settings do not focus the field causing validation errors
  • MDL-88076 - URLs which should not redirect the MFA check do not work except the last one
  • MDL-88039 - MathJax failed when there is a loaded expression
  • MDL-88012 - Mails sent within the same SMTP session are assigned the same MessageID
  • MDL-88009 - Footer JavaScript sanitises footer popover and can remove content
  • MDL-87967 - Disabled core/toggle elements do not show tooltips
  • MDL-87959 - Moodle LMS to Marketplace integration
  • MDL-87957 - BigBlueButton Meeting events data processing sometimes fails on database write
  • MDL-87935 - Ollama error response is incorrectly handled
  • MDL-87903 - Hooks callback cache should also be on shared disk as well as local cache
  • MDL-87795 - The system always tries to send push messages via AirNotifier to devices that have been inactive for months
  • MDL-87778 - Deep linking to /admin/tasklogs.php?logid=12345 doesn't work after login redirect
  • MDL-87708 - Remove MoodleNet services
  • MDL-87657 - Report builder - Custom Reports - Conditions - Select cohort is not retained
  • MDL-87632 - Activity completion shows incorrect module when subsection has restricted access
  • MDL-87597 - Messaging drawer requires double click to reopen
  • MDL-87548 - Uploading image from Wikimedia fails on certain images
  • MDL-87535 - Students can see quiz dates and completion conditions during an attempt in secure layout
  • MDL-87509 - BigBlueButton Protected Recordings can only be accessed once
  • MDL-87492 - Quiz attempts can get stuck in "Submitted" state
  • MDL-87471 - TinyMCE's is_autosave_stale() method uses wrong context and doesn't detect deleted draft areas
  • MDL-87190 - File upload displays wrong error message if you drag and drop a folder into the file-picker
  • MDL-87187 - BigBlueButton restore code incorrectly uses apply_date_offset for timemodified and timecreated
  • MDL-87113 - File upload progress bar gets stuck at 100% when uploading a valid file after attempting to upload unsupported file
  • MDL-87100 - Infer upgrade note issue number based on current Git branch
  • MDL-87075 - User's role still visible in profile when "Allow role to view" and "Allow role assignments" is disabled
  • MDL-86989 - "Edit this learning plan" link not clickable when editing template-based learning plan
  • MDL-86839 - Make grunt watch respect force flag
  • MDL-86714 - 404 error being displayed on a restored SCORM activity
  • MDL-86298 - File-picker with file-type restrictions allowed files to be renamed to any extensions
  • MDL-84780 - Drag-and-drop upload does not respect disabled modules

Accessibility fixes and improvements

  • MDL-77649 - Glossary uses layout tables to render categories and entries
  • MDL-87955 - Accessibility issues on the forum Manage subscribers page
  • MDL-87949 - Insufficient colour contrast when adding Rubric criterion
  • MDL-87993 - Create a screen reader-only toast feature
  • MDL-87810 - Insufficient colour contrast for links in quiz questions and feedback text
  • MDL-81608 - Elements on the Quiz question edit page don't meet WCAG target area requirements
  • MDL-88122 - Empty breadcrumb accessibility issue in course navbar
  • MDL-87919 - Insufficient colour contrast accessibility issue in selected restricted subsections in course index
  • MDL-87600 - Skipped heading levels accessibility issue on user Grades and Preferences pages
  • MDL-86616 - Filepicker file restrictions should be linked to the file input element using aria-describedby
  • MDL-85902 - "Next activity" links not structured as navigation areas (9.2 RGAA criteria)
  • MDL-85451 - Incorrect heading levels in Timeline block
  • MDL-77209 - Links within form help popovers should open in a new tab

Performance fixes and improvements

  • MDL-85637 - SQL performance issue when finding the latest version of questions (can make qbanks unusable)
  • MDL-86386 - Ad-hoc task mod_qbank\task\transfer_question_categories causes performance issues on large sites
  • MDL-87605 - Serve minified TinyMCE plugin JavaScript files

Security improvements

  • MDL-83096 - LTI 1.3 new window not triggering completion event
  • MDL-86165 - BigBlueButton recording actions (publish, unpublish, protect, delete, edit, import) are not logged, breaking expected auditability
  • MDL-88145 - cURL security helper method call order check contains a typo
  • MDL-87331 - Course edit returnurl triggers blocking by WAF applications

Security fixes

  • MSA-26-0005 - SQL injection risk in external database authentication plugin
  • MSA-26-0006 - RCE risk via Moodle's Google Drive repository plugin
  • MSA-26-0007 - Message panel breaks with messages from deleted users (messaging DoS risk)
  • MSA-26-0009 - CSRF risk in reset penalty rules functionality
  • MSA-26-0010 - Upgrade AWS SDK for PHP including security fix (upstream)
  • MSA-26-0011 - CSRF and missing capability check in admin/mnet/peers.php