Moodle
by Moodle
Source repositories
CVEs (632)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-36393 | Cri | 0.68 | 9.8 | 0.52 | Mar 6, 2023 | In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. | ||
| CVE-2017-2641 | Cri | 0.68 | 9.8 | 0.15 | Mar 26, 2017 | In Moodle 2.x and 3.x, SQL injection can occur via user preferences. | ||
| CVE-2021-36394 | Cri | 0.64 | 9.8 | 0.07 | Mar 6, 2023 | In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. | ||
| CVE-2021-36392 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2023 | In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. | ||
| CVE-2022-40315 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2022 | A limited SQL injection risk was identified in the "browse list of users" site administration page. | ||
| CVE-2021-21809 | Cri | 0.64 | 9.1 | 0.24 | Jun 23, 2021 | A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities. | ||
| CVE-2022-0332 | Cri | 0.63 | 9.8 | 0.45 | Jan 25, 2022 | A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data. | ||
| CVE-2018-1133 | Hig | 0.63 | 8.8 | 0.32 | May 25, 2018 | An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection. | ||
| CVE-2019-14880 | Cri | 0.59 | 9.1 | 0.01 | Mar 31, 2020 | A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise. | ||
| CVE-2016-9187 | Hig | 0.58 | 8.8 | 0.04 | Nov 4, 2016 | Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | ||
| CVE-2016-9186 | Hig | 0.58 | 8.8 | 0.04 | Nov 4, 2016 | Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | ||
| CVE-2025-67847 | Hig | 0.57 | 8.8 | 0.01 | Jan 23, 2026 | A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation… | ||
| CVE-2023-28333 | Cri | 0.57 | 9.8 | 0.01 | Mar 23, 2023 | The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS). | ||
| CVE-2022-30600 | Cri | 0.57 | 9.8 | 0.05 | May 18, 2022 | A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed. | ||
| CVE-2022-30599 | Cri | 0.57 | 9.8 | 0.01 | May 18, 2022 | A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria. | ||
| CVE-2021-3943 | Cri | 0.57 | 9.8 | 0.02 | Nov 22, 2021 | A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified. | ||
| CVE-2020-25629 | Hig | 0.57 | 8.8 | 0.01 | Dec 8, 2020 | A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5… | ||
| CVE-2020-14321 | Hig | 0.54 | 8.8 | 0.16 | Aug 16, 2022 | In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course. | ||
| CVE-2024-43434 | Hig | 0.53 | 8.1 | 0.01 | Nov 7, 2024 | The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability. | ||
| CVE-2020-1692 | Hig | 0.53 | 8.1 | 0.01 | Feb 17, 2020 | Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course. |
- risk 0.68cvss 9.8epss 0.52
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
- risk 0.68cvss 9.8epss 0.15
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
- risk 0.64cvss 9.8epss 0.07
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
- risk 0.64cvss 9.8epss 0.01
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
- risk 0.64cvss 9.8epss 0.01
A limited SQL injection risk was identified in the "browse list of users" site administration page.
- risk 0.64cvss 9.1epss 0.24
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
- risk 0.63cvss 9.8epss 0.45
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
- risk 0.63cvss 8.8epss 0.32
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
- risk 0.59cvss 9.1epss 0.01
A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.
- risk 0.58cvss 8.8epss 0.04
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
- risk 0.58cvss 8.8epss 0.04
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation…
- risk 0.57cvss 9.8epss 0.01
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).
- risk 0.57cvss 9.8epss 0.05
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
- risk 0.57cvss 9.8epss 0.01
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
- risk 0.57cvss 9.8epss 0.02
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.
- risk 0.57cvss 8.8epss 0.01
A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5…
- risk 0.54cvss 8.8epss 0.16
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
- risk 0.53cvss 8.1epss 0.01
The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
- risk 0.53cvss 8.1epss 0.01
Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.
Page 1 of 32