VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2021-36393CriMar 6, 2023
    risk 0.68cvss 9.8epss 0.52

    In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

  • CVE-2017-2641CriMar 26, 2017
    risk 0.68cvss 9.8epss 0.15

    In Moodle 2.x and 3.x, SQL injection can occur via user preferences.

  • CVE-2021-36394CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.07

    In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

  • CVE-2021-36392CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.

  • CVE-2022-40315CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    A limited SQL injection risk was identified in the "browse list of users" site administration page.

  • CVE-2021-21809CriJun 23, 2021
    risk 0.64cvss 9.1epss 0.24

    A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.

  • CVE-2022-0332CriJan 25, 2022
    risk 0.63cvss 9.8epss 0.45

    A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.

  • CVE-2018-1133HigMay 25, 2018
    risk 0.63cvss 8.8epss 0.32

    An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.

  • CVE-2019-14880CriMar 31, 2020
    risk 0.59cvss 9.1epss 0.01

    A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

  • CVE-2016-9187HigNov 4, 2016
    risk 0.58cvss 8.8epss 0.04

    Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

  • CVE-2016-9186HigNov 4, 2016
    risk 0.58cvss 8.8epss 0.04

    Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

  • CVE-2025-67847HigJan 23, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation…

  • CVE-2023-28333CriMar 23, 2023
    risk 0.57cvss 9.8epss 0.01

    The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

  • CVE-2022-30600CriMay 18, 2022
    risk 0.57cvss 9.8epss 0.05

    A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

  • CVE-2022-30599CriMay 18, 2022
    risk 0.57cvss 9.8epss 0.01

    A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.

  • CVE-2021-3943CriNov 22, 2021
    risk 0.57cvss 9.8epss 0.02

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.

  • CVE-2020-25629HigDec 8, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5…

  • CVE-2020-14321HigAug 16, 2022
    risk 0.54cvss 8.8epss 0.16

    In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.

  • CVE-2024-43434HigNov 7, 2024
    risk 0.53cvss 8.1epss 0.01

    The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.

  • CVE-2020-1692HigFeb 17, 2020
    risk 0.53cvss 8.1epss 0.01

    Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

Page 1 of 32