Moodle 4.5.13
Unsupported Moodle Version
This version of Moodle is no longer supported for general bug fixes.
You are encouraged to upgrade to a supported version of Moodle.
You are encouraged to upgrade to a supported version of Moodle.
Release date: 10 August 2026
Here is the full list of fixed issues in 4.5.13.
General fixes and improvements
- MDL-88878 - OpenAI AI provider: json_encode() escapes slashes in model name, causing 404 with OpenAI-compatible providers
Accessibility fixes and improvements
- MDL-89252 - "Add a new category" button in custom fields administration cannot be activated by keyboard
- MDL-88964 - TinyMCE editor accessibility issues
- MDL-88956 - Assignment editing: Missing accessible label on the "Word limit" field
- MDL-88951 - TinyMCE image details modal: Fake headings, delete image button issues
- MDL-88354 - Empty link in the sortable list dialogue
- MDL-89221 - The recently accessed courses block's pagination controls obscures block controls (move/action menu)
- MDL-88963 - Target size below 24x24px minimum for block action buttons
- MDL-88962 - Course Home edit mode: No status message when moving sections
- MDL-88961 - Calendar: Day event tooltip not dismissable without moving focus
- MDL-88958 - Accessibility issues in Comments
- MDL-88957 - Accessibility issues with the custom fields admin pages
- MDL-88955 - Assignment grading: Sticky table header is misplaced at 400% zoom
- MDL-88932 - Chevron icon on the message drawer conversation item has insufficient contrast on hover
- MDL-88833 - Nested search landmark role involving core/search_input_auto
- MDL-88528 - Logo image breaks main menu on small screens (mobile)
- MDL-88173 - qtype_multichoice: Screen readers do not announce question text for radio button groups
- MDL-71231 - Make previous/next chapter links for the book activity more meaningful
Security fixes
- MSA-26-0030 - SSRF risk in URL downloader (bypass some blocked hosts)
- MSA-26-0031 - SQL injection risk in question bank web service
- MSA-26-0032 - User profile information disclosure via grade web service
- MSA-26-0033 - Arbitrary class instantiation via audience classname in core_reportbuilder
- MSA-26-0034 - XSS risk in forum post templates
- MSA-26-0035 - Manual enrolment does not correctly observe disabled state of plugin
- MSA-26-0036 - Incorrect capability check in AI editor placement "generate image" service
- MSA-26-0039 - Minor XSS risk via password reset link
- MSA-26-0040 - User list filters do not respect user profile field visibility
- MSA-26-0041 - CSRF risk in XML grade imports