VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2015-5340MedFeb 22, 2016
    risk 0.21cvss 4.3epss 0.01

    Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not consider the moodle/badges:viewbadges capability, which allows remote authenticated users to obtain sensitive badge information via a request involving (1) badges/overview.php or (2)…

  • CVE-2015-5339MedFeb 22, 2016
    risk 0.21cvss 4.3epss 0.01

    The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenticated users to obtain…

  • CVE-2015-5335MedFeb 22, 2016
    risk 0.21cvss 4.3epss 0.01

    Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for requests that send statistics…

  • CVE-2015-5331MedFeb 22, 2016
    risk 0.21cvss 4.3epss 0.01

    Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.

  • CVE-2015-5268MedFeb 22, 2016
    risk 0.21cvss 4.3epss 0.02

    The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.

  • CVE-2015-5265MedFeb 22, 2016
    risk 0.21cvss 4.3epss 0.01

    The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary files by using a…

  • CVE-2025-53021MedJun 24, 2025
    risk 0.20cvss 4.2epss 0.00

    A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being…

  • CVE-2022-0333LowJan 25, 2022
    risk 0.18cvss 3.8epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.

  • CVE-2012-1160LowNov 14, 2019
    risk 0.18cvss 2.7epss 0.01

    Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php

  • CVE-2025-67852LowFeb 3, 2026
    risk 0.16cvss 3.5epss 0.00

    A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could…

  • CVE-2025-3635LowApr 25, 2025
    risk 0.16cvss 3.5epss 0.00

    A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.

  • CVE-2024-25983LowFeb 19, 2024
    risk 0.16cvss 3.5epss 0.01

    Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

  • CVE-2023-5551LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.

  • CVE-2023-5549LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.

  • CVE-2023-5548LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

  • CVE-2023-5547LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    The course upload preview contained an XSS risk for users uploading unsafe data.

  • CVE-2023-5545LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    H5P metadata automatically populated the author with the user's username, which could be sensitive information.

  • CVE-2023-5542LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Students in "Only see own membership" groups could see other students in the group, which should be hidden.

  • CVE-2023-5541LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

  • CVE-2025-3637LowApr 25, 2025
    risk 0.13cvss 3.1epss 0.00

    A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and…

Page 15 of 32