VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2025-26533HigFeb 24, 2025
    risk 0.46cvss 8.1epss 0.01

    An SQL injection risk was identified in the module list filter within course search.

  • CVE-2022-40313HigSep 30, 2022
    risk 0.46cvss 7.1epss 0.01

    Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

  • CVE-2018-1137HigMay 25, 2018
    risk 0.46cvss 8.1epss 0.01

    An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.

  • CVE-2015-5332MedFeb 22, 2016
    risk 0.44cvss 6.8epss 0.02

    Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

  • CVE-2025-62399HigOct 23, 2025
    risk 0.42cvss 7.5epss 0.00

    Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

  • CVE-2025-32044HigApr 25, 2025
    risk 0.42cvss 7.5epss 0.01

    A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with…

  • CVE-2024-45690HigNov 20, 2024
    risk 0.42cvss 7.5epss 0.00

    A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

  • CVE-2024-38275HigJun 18, 2024
    risk 0.42cvss 7.5epss 0.00

    The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

  • CVE-2024-34004MedMay 31, 2024
    risk 0.42cvss 6.5epss 0.00

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

  • CVE-2024-25978HigFeb 19, 2024
    risk 0.42cvss 7.5epss 0.01

    Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

  • CVE-2024-1439MedFeb 12, 2024
    risk 0.42cvss 6.5epss 0.00

    Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

  • CVE-2022-39183MedJan 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.

  • CVE-2021-40693MedSep 29, 2022
    risk 0.42cvss 6.5epss 0.01

    An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.

  • CVE-2020-25699HigNov 19, 2020
    risk 0.42cvss 7.5epss 0.02

    In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed…

  • CVE-2020-25698HigNov 19, 2020
    risk 0.42cvss 7.5epss 0.02

    Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2…

  • CVE-2020-10738HigMay 21, 2020
    risk 0.42cvss 7.5epss 0.03

    A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in…

  • CVE-2012-1156HigNov 14, 2019
    risk 0.42cvss 7.5epss 0.02

    Moodle before 2.2.2 has users' private files included in course backups

  • CVE-2019-10154HigJun 26, 2019
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

  • CVE-2019-6970HigMar 21, 2019
    risk 0.42cvss 7.5epss 0.01

    Moodle 3.5.x before 3.5.4 allows SSRF.

  • CVE-2018-1043MedJan 22, 2018
    risk 0.42cvss 6.5epss 0.01

    In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.

Page 4 of 32