VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2025-26528LowFeb 24, 2025
    risk 0.00cvss 3.4epss 0.00

    The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.

  • CVE-2025-26527MedFeb 24, 2025
    risk 0.00cvss 5.3epss 0.00

    Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.

  • CVE-2025-26526MedFeb 24, 2025
    risk 0.00cvss 6.5epss 0.00

    Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.

  • CVE-2025-26525HigFeb 24, 2025
    risk 0.00cvss 8.6epss 0.00

    Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).

  • CVE-2024-48900MedNov 13, 2024
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.

  • CVE-2024-43437MedNov 11, 2024
    risk 0.00cvss 5.4epss 0.00

    A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.

  • CVE-2024-43435MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.

  • CVE-2024-43433MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

  • CVE-2024-43432MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

  • CVE-2024-43430MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.

  • CVE-2024-43429MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.

  • CVE-2024-43427LowNov 11, 2024
    risk 0.00cvss 3.7epss 0.00

    A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party.

  • CVE-2024-43428HigNov 7, 2024
    risk 0.00cvss 7.7epss 0.00

    To address a cache poisoning risk in Moodle, additional validation for local storage was required.

  • CVE-2024-43426HigNov 7, 2024
    risk 0.00cvss 7.5epss 0.01

    A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.

  • CVE-2024-34009HigMay 31, 2024
    risk 0.00cvss 7.5epss 0.00

    Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.

  • CVE-2024-34007HigMay 31, 2024
    risk 0.00cvss 8.8epss 0.00

    The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

  • CVE-2024-34003MedMay 31, 2024
    risk 0.00cvss 5.9epss 0.00

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

  • CVE-2024-34002MedMay 31, 2024
    risk 0.00cvss 6.5epss 0.00

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

  • CVE-2024-33999CriMay 31, 2024
    risk 0.00cvss 9.8epss 0.01

    The referrer URL used by MFA required additional sanitizing, rather than being used directly.

  • CVE-2024-33996MedMay 31, 2024
    risk 0.00cvss 6.2epss 0.00

    Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.

Page 17 of 32