VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2024-43438HigNov 7, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.

  • CVE-2024-43431HigNov 7, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.

  • CVE-2021-36396HigMar 6, 2023
    risk 0.49cvss 7.5epss 0.01

    In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.

  • CVE-2021-36395HigMar 6, 2023
    risk 0.49cvss 7.5epss 0.01

    In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.

  • CVE-2020-14322HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.

  • CVE-2021-32476HigMar 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.

  • CVE-2020-25630HigDec 8, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and…

  • CVE-2012-1170HigNov 14, 2019
    risk 0.49cvss 7.5epss 0.01

    Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough

  • CVE-2012-1155HigNov 14, 2019
    risk 0.49cvss 7.5epss 0.02

    Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to

  • CVE-2016-7919HigOct 28, 2016
    risk 0.49cvss 7.5epss 0.02

    Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting…

  • CVE-2024-34001HigMay 31, 2024
    risk 0.48cvss 8.4epss 0.00

    Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

  • CVE-2016-7038HigJan 20, 2017
    risk 0.48cvss 7.3epss 0.01

    In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

  • CVE-2026-26046HigFeb 21, 2026
    risk 0.47cvss 7.2epss 0.12

    A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an…

  • CVE-2021-47857HigJan 21, 2026
    risk 0.47cvss 7.2epss 0.00

    Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code…

  • CVE-2024-43436HigNov 7, 2024
    risk 0.47cvss 7.2epss 0.01

    A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.

  • CVE-2020-1756HigAug 16, 2022
    risk 0.47cvss 7.2epss 0.01

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

  • CVE-2021-32474HigMar 11, 2022
    risk 0.47cvss 7.2epss 0.01

    An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier…

  • CVE-2021-20187HigJan 28, 2021
    risk 0.47cvss 7.2epss 0.02

    It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.

  • CVE-2025-67848HigFeb 3, 2026
    risk 0.46cvss 8.1epss 0.00

    A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling…

  • CVE-2025-3625HigApr 25, 2025
    risk 0.46cvss 7.1epss 0.00

    A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).

Page 3 of 32