VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2012-1168HigNov 14, 2019
    risk 0.53cvss 8.2epss 0.02

    Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

  • CVE-2018-1137HigMay 25, 2018
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.

  • CVE-2018-14630HigSep 17, 2018
    risk 0.51cvss 8.8epss 0.04

    moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within…

  • CVE-2025-3642HigApr 25, 2025
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.

  • CVE-2025-3641HigApr 25, 2025
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.

  • CVE-2025-3638HigApr 25, 2025
    risk 0.50cvss 8.8epss 0.00

    A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.

  • CVE-2024-38276HigJun 18, 2024
    risk 0.50cvss 8.8epss 0.00

    Incorrect CSRF token checks resulted in multiple CSRF risks.

  • CVE-2024-34008HigMay 31, 2024
    risk 0.50cvss 8.8epss 0.00

    Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.

  • CVE-2023-28335HigMar 23, 2023
    risk 0.50cvss 8.8epss 0.00

    The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.

  • CVE-2023-28329HigMar 23, 2023
    risk 0.50cvss 8.8epss 0.01

    Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

  • CVE-2022-0983HigMar 25, 2022
    risk 0.50cvss 8.8epss 0.01

    An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

  • CVE-2022-0335HigJan 25, 2022
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.

  • CVE-2021-43559HigNov 22, 2021
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

  • CVE-2019-10186HigJul 31, 2019
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.

  • CVE-2019-3849HigMar 26, 2019
    risk 0.50cvss 8.8epss 0.01

    A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.

  • CVE-2018-14631HigSep 17, 2018
    risk 0.50cvss 8.8epss 0.02

    moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected…

  • CVE-2016-3734HigApr 20, 2017
    risk 0.50cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.

  • CVE-2016-2157HigMay 22, 2016
    risk 0.50cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests…

  • CVE-2015-5338HigFeb 22, 2016
    risk 0.50cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary users for requests to (1)…

  • CVE-2025-67853HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.

Page 2 of 32