Moodle
by Moodle
Source repositories
CVEs (632)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-48897 | Med | 0.28 | 4.3 | 0.00 | Nov 18, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify. | ||
| CVE-2024-48896 | Med | 0.28 | 4.3 | 0.00 | Nov 18, 2024 | A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site. | ||
| CVE-2024-43439 | Med | 0.28 | 5.4 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk. | ||
| CVE-2024-38277 | Med | 0.28 | 5.4 | 0.00 | Jun 18, 2024 | A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two. | ||
| CVE-2024-38273 | Med | 0.28 | 5.4 | 0.00 | Jun 18, 2024 | Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access. | ||
| CVE-2024-33998 | Med | 0.28 | 5.4 | 0.00 | May 31, 2024 | Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features. | ||
| CVE-2022-40316 | Med | 0.28 | 4.3 | 0.01 | Sep 30, 2022 | The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. | ||
| CVE-2021-40695 | Med | 0.28 | 4.3 | 0.01 | Sep 29, 2022 | It was possible for a student to view their quiz grade before it had been released, using a quiz web service. | ||
| CVE-2021-40692 | Med | 0.28 | 4.3 | 0.01 | Sep 29, 2022 | Insufficient capability checks made it possible for teachers to download users outside of their courses. | ||
| CVE-2021-40691 | Med | 0.28 | 4.3 | 0.01 | Sep 29, 2022 | A session hijack risk was identified in the Shibboleth authentication plugin. | ||
| CVE-2020-1754 | Med | 0.28 | 4.3 | 0.01 | Aug 5, 2022 | In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups. | ||
| CVE-2020-1691 | Med | 0.28 | 5.4 | 0.01 | Aug 5, 2022 | In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting. | ||
| CVE-2022-30597 | Med | 0.28 | 5.3 | 0.01 | May 18, 2022 | A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field. | ||
| CVE-2022-30596 | Med | 0.28 | 5.4 | 0.01 | May 18, 2022 | A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk. | ||
| CVE-2021-32477 | Med | 0.28 | 4.3 | 0.01 | Mar 11, 2022 | The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected. | ||
| CVE-2021-32472 | Med | 0.28 | 4.3 | 0.01 | Mar 11, 2022 | Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected. | ||
| CVE-2019-14829 | Med | 0.28 | 4.3 | 0.01 | Mar 19, 2021 | A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode. | ||
| CVE-2019-14828 | Med | 0.28 | 4.3 | 0.01 | Mar 19, 2021 | A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be… | ||
| CVE-2021-20282 | Med | 0.28 | 5.3 | 0.01 | Mar 15, 2021 | When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. | ||
| CVE-2021-20281 | Med | 0.28 | 5.3 | 0.01 | Mar 15, 2021 | It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. |
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.
- risk 0.28cvss 5.4epss 0.00
A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.
- risk 0.28cvss 5.4epss 0.00
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
- risk 0.28cvss 5.4epss 0.00
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
- risk 0.28cvss 5.4epss 0.00
Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.
- risk 0.28cvss 4.3epss 0.01
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
- risk 0.28cvss 4.3epss 0.01
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
- risk 0.28cvss 4.3epss 0.01
Insufficient capability checks made it possible for teachers to download users outside of their courses.
- risk 0.28cvss 4.3epss 0.01
A session hijack risk was identified in the Shibboleth authentication plugin.
- risk 0.28cvss 4.3epss 0.01
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
- risk 0.28cvss 5.4epss 0.01
In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.
- risk 0.28cvss 5.3epss 0.01
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
- risk 0.28cvss 5.4epss 0.01
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
- risk 0.28cvss 4.3epss 0.01
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.
- risk 0.28cvss 4.3epss 0.01
Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected.
- risk 0.28cvss 4.3epss 0.01
A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.
- risk 0.28cvss 4.3epss 0.01
A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be…
- risk 0.28cvss 5.3epss 0.01
When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
- risk 0.28cvss 5.3epss 0.01
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Page 10 of 32