Moodle
by Moodle
Source repositories
CVEs (632)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-26528 | Low | 0.00 | 3.4 | 0.00 | Feb 24, 2025 | The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk. | ||
| CVE-2025-26527 | Med | 0.00 | 5.3 | 0.00 | Feb 24, 2025 | Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block. | ||
| CVE-2025-26526 | Med | 0.00 | 6.5 | 0.00 | Feb 24, 2025 | Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities. | ||
| CVE-2025-26525 | Hig | 0.00 | 8.6 | 0.00 | Feb 24, 2025 | Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed). | ||
| CVE-2024-48900 | Med | 0.00 | 4.3 | 0.00 | Nov 13, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to. | ||
| CVE-2024-43437 | Med | 0.00 | 5.4 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files. | ||
| CVE-2024-43435 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary. | ||
| CVE-2024-43433 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users. | ||
| CVE-2024-43432 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs. | ||
| CVE-2024-43430 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. External API access to Quiz can override contained insufficient access control. | ||
| CVE-2024-43429 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information. | ||
| CVE-2024-43427 | Low | 0.00 | 3.7 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party. | ||
| CVE-2024-43428 | Hig | 0.00 | 7.7 | 0.00 | Nov 7, 2024 | To address a cache poisoning risk in Moodle, additional validation for local storage was required. | ||
| CVE-2024-43426 | Hig | 0.00 | 7.5 | 0.01 | Nov 7, 2024 | A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed. | ||
| CVE-2024-34009 | Hig | 0.00 | 7.5 | 0.00 | May 31, 2024 | Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized. | ||
| CVE-2024-34007 | Hig | 0.00 | 8.8 | 0.00 | May 31, 2024 | The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF. | ||
| CVE-2024-34003 | Med | 0.00 | 5.9 | 0.00 | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include. | ||
| CVE-2024-34002 | Med | 0.00 | 6.5 | 0.00 | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local file include. | ||
| CVE-2024-33999 | Cri | 0.00 | 9.8 | 0.01 | May 31, 2024 | The referrer URL used by MFA required additional sanitizing, rather than being used directly. | ||
| CVE-2024-33996 | Med | 0.00 | 6.2 | 0.00 | May 31, 2024 | Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to. |
- risk 0.00cvss 3.4epss 0.00
The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
- risk 0.00cvss 5.3epss 0.00
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
- risk 0.00cvss 6.5epss 0.00
Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.
- risk 0.00cvss 8.6epss 0.00
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).
- risk 0.00cvss 4.3epss 0.00
A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.
- risk 0.00cvss 5.4epss 0.00
A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.
- risk 0.00cvss 3.7epss 0.00
A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party.
- risk 0.00cvss 7.7epss 0.00
To address a cache poisoning risk in Moodle, additional validation for local storage was required.
- risk 0.00cvss 7.5epss 0.01
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
- risk 0.00cvss 7.5epss 0.00
Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.
- risk 0.00cvss 8.8epss 0.00
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
- risk 0.00cvss 5.9epss 0.00
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
- risk 0.00cvss 6.5epss 0.00
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
- risk 0.00cvss 9.8epss 0.01
The referrer URL used by MFA required additional sanitizing, rather than being used directly.
- risk 0.00cvss 6.2epss 0.00
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.
Page 17 of 32