Moodle
by Moodle
Source repositories
CVEs (632)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2012-1168 | Hig | 0.53 | 8.2 | 0.02 | Nov 14, 2019 | Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. | ||
| CVE-2018-1137 | Hig | 0.53 | 8.1 | 0.02 | May 25, 2018 | An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack. | ||
| CVE-2018-14630 | Hig | 0.51 | 8.8 | 0.04 | Sep 17, 2018 | moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within… | ||
| CVE-2025-3642 | Hig | 0.50 | 8.8 | 0.01 | Apr 25, 2025 | A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled. | ||
| CVE-2025-3641 | Hig | 0.50 | 8.8 | 0.01 | Apr 25, 2025 | A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled. | ||
| CVE-2025-3638 | Hig | 0.50 | 8.8 | 0.00 | Apr 25, 2025 | A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk. | ||
| CVE-2024-38276 | Hig | 0.50 | 8.8 | 0.00 | Jun 18, 2024 | Incorrect CSRF token checks resulted in multiple CSRF risks. | ||
| CVE-2024-34008 | Hig | 0.50 | 8.8 | 0.00 | May 31, 2024 | Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk. | ||
| CVE-2023-28335 | Hig | 0.50 | 8.8 | 0.00 | Mar 23, 2023 | The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk. | ||
| CVE-2023-28329 | Hig | 0.50 | 8.8 | 0.01 | Mar 23, 2023 | Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers). | ||
| CVE-2022-0983 | Hig | 0.50 | 8.8 | 0.01 | Mar 25, 2022 | An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default. | ||
| CVE-2022-0335 | Hig | 0.50 | 8.8 | 0.01 | Jan 25, 2022 | A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk. | ||
| CVE-2021-43559 | Hig | 0.50 | 8.8 | 0.01 | Nov 22, 2021 | A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk. | ||
| CVE-2019-10186 | Hig | 0.50 | 8.8 | 0.01 | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool. | ||
| CVE-2019-3849 | Hig | 0.50 | 8.8 | 0.01 | Mar 26, 2019 | A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site. | ||
| CVE-2018-14631 | Hig | 0.50 | 8.8 | 0.02 | Sep 17, 2018 | moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected… | ||
| CVE-2016-3734 | Hig | 0.50 | 8.8 | 0.01 | Apr 20, 2017 | Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read. | ||
| CVE-2016-2157 | Hig | 0.50 | 8.8 | 0.01 | May 22, 2016 | Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests… | ||
| CVE-2015-5338 | Hig | 0.50 | 8.8 | 0.01 | Feb 22, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary users for requests to (1)… | ||
| CVE-2025-67853 | Hig | 0.49 | 7.5 | 0.00 | Feb 3, 2026 | A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts. |
- risk 0.53cvss 8.2epss 0.02
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
- risk 0.53cvss 8.1epss 0.02
An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
- risk 0.51cvss 8.8epss 0.04
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within…
- risk 0.50cvss 8.8epss 0.01
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.
- risk 0.50cvss 8.8epss 0.01
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.
- risk 0.50cvss 8.8epss 0.00
A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.
- risk 0.50cvss 8.8epss 0.00
Incorrect CSRF token checks resulted in multiple CSRF risks.
- risk 0.50cvss 8.8epss 0.00
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
- risk 0.50cvss 8.8epss 0.00
The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.
- risk 0.50cvss 8.8epss 0.01
Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).
- risk 0.50cvss 8.8epss 0.01
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
- risk 0.50cvss 8.8epss 0.01
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.
- risk 0.50cvss 8.8epss 0.01
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
- risk 0.50cvss 8.8epss 0.01
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
- risk 0.50cvss 8.8epss 0.01
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
- risk 0.50cvss 8.8epss 0.02
moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected…
- risk 0.50cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.
- risk 0.50cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests…
- risk 0.50cvss 8.8epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary users for requests to (1)…
- risk 0.49cvss 7.5epss 0.00
A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.
Page 2 of 32