CVE-2025-63564

SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests

  • Published Sep 23, 2026
  • CVSS 9.8 critical
  • 0.5% chance of exploitation in the next 30 days (EPSS)

CVE-2025-63564 at the National Vulnerability Database