VYPR

Moodle

by Moodle

Source repositories

CVEs (644)

  • CVE-2025-53021MedJun 24, 2025
    risk 0.20cvss 4.2epss 0.00

    A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being…

  • CVE-2026-102587LowSep 30, 2026
    risk 0.18cvss 2.7epss —

    A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted to view directly, resulting in unauthorized…

  • CVE-2026-102583LowSep 30, 2026
    risk 0.18cvss 2.7epss —

    A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the required capability. This flaw permits unauthorized users to…

  • CVE-2022-0333LowJan 25, 2022
    risk 0.18cvss 3.8epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.

  • CVE-2012-1160LowNov 14, 2019
    risk 0.18cvss 2.7epss 0.01

    Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php

  • CVE-2025-67852LowFeb 3, 2026
    risk 0.16cvss 3.5epss 0.00

    A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could…

  • CVE-2025-3635LowApr 25, 2025
    risk 0.16cvss 3.5epss 0.00

    A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.

  • CVE-2024-25983LowFeb 19, 2024
    risk 0.16cvss 3.5epss 0.01

    Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

  • CVE-2026-102582LowSep 30, 2026
    risk 0.14cvss 2.2epss —

    A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its URL. Consequently, an authorized user could manage…

  • CVE-2026-102580LowSep 30, 2026
    risk 0.14cvss 2.2epss —

    A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of internal program objects, which may…

  • CVE-2023-5551LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.

  • CVE-2023-5549LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.

  • CVE-2023-5548LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

  • CVE-2023-5547LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    The course upload preview contained an XSS risk for users uploading unsafe data.

  • CVE-2023-5545LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    H5P metadata automatically populated the author with the user's username, which could be sensitive information.

  • CVE-2023-5542LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Students in "Only see own membership" groups could see other students in the group, which should be hidden.

  • CVE-2023-5541LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

  • CVE-2025-3637LowApr 25, 2025
    risk 0.13cvss 3.1epss 0.00

    A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and…

  • CVE-2019-10133LowJun 26, 2019
    risk 0.13cvss 3.1epss 0.01

    A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

  • CVE-2024-43425HigNov 7, 2024
    risk 0.10cvss 8.1epss 0.88

    A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

Page 16 of 33