Moodle
by Moodle
Source repositories
CVEs (644)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-53021 | Med | 0.20 | 4.2 | 0.00 | Jun 24, 2025 | A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being… | ||
| CVE-2026-102587 | Low | 0.18 | 2.7 | — | Sep 30, 2026 | A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized… | ||
| CVE-2026-102583 | Low | 0.18 | 2.7 | — | Sep 30, 2026 | A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to… | ||
| CVE-2022-0333 | Low | 0.18 | 3.8 | 0.01 | Jan 25, 2022 | A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events. | ||
| CVE-2012-1160 | Low | 0.18 | 2.7 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php | ||
| CVE-2025-67852 | Low | 0.16 | 3.5 | 0.00 | Feb 3, 2026 | A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could… | ||
| CVE-2025-3635 | Low | 0.16 | 3.5 | 0.00 | Apr 25, 2025 | A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks. | ||
| CVE-2024-25983 | Low | 0.16 | 3.5 | 0.01 | Feb 19, 2024 | Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page). | ||
| CVE-2026-102582 | Low | 0.14 | 2.2 | — | Sep 30, 2026 | A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage… | ||
| CVE-2026-102580 | Low | 0.14 | 2.2 | — | Sep 30, 2026 | A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may… | ||
| CVE-2023-5551 | Low | 0.14 | 3.3 | 0.00 | Nov 9, 2023 | Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups. | ||
| CVE-2023-5549 | Low | 0.14 | 3.3 | 0.01 | Nov 9, 2023 | Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage. | ||
| CVE-2023-5548 | Low | 0.14 | 3.3 | 0.00 | Nov 9, 2023 | Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. | ||
| CVE-2023-5547 | Low | 0.14 | 3.3 | 0.01 | Nov 9, 2023 | The course upload preview contained an XSS risk for users uploading unsafe data. | ||
| CVE-2023-5545 | Low | 0.14 | 3.3 | 0.01 | Nov 9, 2023 | H5P metadata automatically populated the author with the user's username, which could be sensitive information. | ||
| CVE-2023-5542 | Low | 0.14 | 3.3 | 0.00 | Nov 9, 2023 | Students in "Only see own membership" groups could see other students in the group, which should be hidden. | ||
| CVE-2023-5541 | Low | 0.14 | 3.3 | 0.01 | Nov 9, 2023 | The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content. | ||
| CVE-2025-3637 | Low | 0.13 | 3.1 | 0.00 | Apr 25, 2025 | A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and… | ||
| CVE-2019-10133 | Low | 0.13 | 3.1 | 0.01 | Jun 26, 2019 | A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs. | ||
| CVE-2024-43425 | Hig | 0.10 | 8.1 | 0.88 | Nov 7, 2024 | A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions. |
- risk 0.20cvss 4.2epss 0.00
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being…
- risk 0.18cvss 2.7epss —
A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized…
- risk 0.18cvss 2.7epss —
A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to…
- risk 0.18cvss 3.8epss 0.01
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.
- risk 0.18cvss 2.7epss 0.01
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
- risk 0.16cvss 3.5epss 0.00
A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could…
- risk 0.16cvss 3.5epss 0.00
A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.
- risk 0.16cvss 3.5epss 0.01
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
- risk 0.14cvss 2.2epss —
A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage…
- risk 0.14cvss 2.2epss —
A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may…
- risk 0.14cvss 3.3epss 0.00
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
- risk 0.14cvss 3.3epss 0.01
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
- risk 0.14cvss 3.3epss 0.00
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
- risk 0.14cvss 3.3epss 0.01
The course upload preview contained an XSS risk for users uploading unsafe data.
- risk 0.14cvss 3.3epss 0.01
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
- risk 0.14cvss 3.3epss 0.00
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
- risk 0.14cvss 3.3epss 0.01
The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.
- risk 0.13cvss 3.1epss 0.00
A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and…
- risk 0.13cvss 3.1epss 0.01
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
- risk 0.10cvss 8.1epss 0.88
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
Page 16 of 33