Description In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam. Remediation References CVE-2016-5013 Related Vulnerabilities WordPress Plugin Email Subscribers by Icegram Express-Email Marketing, Newsletters, Automation for WordPress & WooCommerce Multiple Vulnerabilities (4.5.0.1) Oracle Database Server CVE-2010-2407 Vulnerability (CVE-2010-2407) WordPress Plugin WP Real Estate Unspecified Vulnerability (2.0) WordPress Plugin Bricks Remote Code Execution (1.9.6) e107 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2025-11941) Severity Medium Classification CVE-2016-5013 CWE-138 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities