Moodle
by Moodle
Source repositories
CVEs (632)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-43438 | Hig | 0.49 | 7.5 | 0.01 | Nov 7, 2024 | A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report. | ||
| CVE-2024-43431 | Hig | 0.49 | 7.5 | 0.00 | Nov 7, 2024 | A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access. | ||
| CVE-2021-36396 | Hig | 0.49 | 7.5 | 0.01 | Mar 6, 2023 | In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk. | ||
| CVE-2021-36395 | Hig | 0.49 | 7.5 | 0.01 | Mar 6, 2023 | In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service. | ||
| CVE-2020-14322 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service. | ||
| CVE-2021-32476 | Hig | 0.49 | 7.5 | 0.01 | Mar 11, 2022 | A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected. | ||
| CVE-2020-25630 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2020 | A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and… | ||
| CVE-2012-1170 | Hig | 0.49 | 7.5 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough | ||
| CVE-2012-1155 | Hig | 0.49 | 7.5 | 0.02 | Nov 14, 2019 | Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to | ||
| CVE-2016-7919 | Hig | 0.49 | 7.5 | 0.02 | Oct 28, 2016 | Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting… | ||
| CVE-2024-34001 | Hig | 0.48 | 8.4 | 0.00 | May 31, 2024 | Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk. | ||
| CVE-2016-7038 | Hig | 0.48 | 7.3 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed. | ||
| CVE-2026-26046 | Hig | 0.47 | 7.2 | 0.12 | Feb 21, 2026 | A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an… | ||
| CVE-2021-47857 | Hig | 0.47 | 7.2 | 0.00 | Jan 21, 2026 | Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code… | ||
| CVE-2024-43436 | Hig | 0.47 | 7.2 | 0.01 | Nov 7, 2024 | A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators. | ||
| CVE-2020-1756 | Hig | 0.47 | 7.2 | 0.01 | Aug 16, 2022 | In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool. | ||
| CVE-2021-32474 | Hig | 0.47 | 7.2 | 0.01 | Mar 11, 2022 | An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier… | ||
| CVE-2021-20187 | Hig | 0.47 | 7.2 | 0.02 | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication. | ||
| CVE-2025-67848 | Hig | 0.46 | 8.1 | 0.00 | Feb 3, 2026 | A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling… | ||
| CVE-2025-3625 | Hig | 0.46 | 7.1 | 0.00 | Apr 25, 2025 | A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA). |
- risk 0.49cvss 7.5epss 0.01
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.
- risk 0.49cvss 7.5epss 0.00
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
- risk 0.49cvss 7.5epss 0.01
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
- risk 0.49cvss 7.5epss 0.01
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.
- risk 0.49cvss 7.5epss 0.01
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.
- risk 0.49cvss 7.5epss 0.01
A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
- risk 0.49cvss 7.5epss 0.01
A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and…
- risk 0.49cvss 7.5epss 0.01
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
- risk 0.49cvss 7.5epss 0.02
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
- risk 0.49cvss 7.5epss 0.02
Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting…
- risk 0.48cvss 8.4epss 0.00
Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
- risk 0.48cvss 7.3epss 0.01
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
- risk 0.47cvss 7.2epss 0.12
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an…
- risk 0.47cvss 7.2epss 0.00
Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code…
- risk 0.47cvss 7.2epss 0.01
A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.
- risk 0.47cvss 7.2epss 0.01
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.
- risk 0.47cvss 7.2epss 0.01
An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier…
- risk 0.47cvss 7.2epss 0.02
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.
- risk 0.46cvss 8.1epss 0.00
A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling…
- risk 0.46cvss 7.1epss 0.00
A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).
Page 3 of 32