Moodle
by Moodle
Source repositories
CVEs (632)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-26533 | Hig | 0.46 | 8.1 | 0.01 | Feb 24, 2025 | An SQL injection risk was identified in the module list filter within course search. | ||
| CVE-2022-40313 | Hig | 0.46 | 7.1 | 0.01 | Sep 30, 2022 | Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load. | ||
| CVE-2018-1137 | Hig | 0.46 | 8.1 | 0.01 | May 25, 2018 | An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack. | ||
| CVE-2015-5332 | Med | 0.44 | 6.8 | 0.02 | Feb 22, 2016 | Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature. | ||
| CVE-2025-62399 | Hig | 0.42 | 7.5 | 0.00 | Oct 23, 2025 | Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks. | ||
| CVE-2025-32044 | Hig | 0.42 | 7.5 | 0.01 | Apr 25, 2025 | A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with… | ||
| CVE-2024-45690 | Hig | 0.42 | 7.5 | 0.00 | Nov 20, 2024 | A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts. | ||
| CVE-2024-38275 | Hig | 0.42 | 7.5 | 0.00 | Jun 18, 2024 | The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs. | ||
| CVE-2024-34004 | Med | 0.42 | 6.5 | 0.00 | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include. | ||
| CVE-2024-25978 | Hig | 0.42 | 7.5 | 0.01 | Feb 19, 2024 | Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality. | ||
| CVE-2024-1439 | Med | 0.42 | 6.5 | 0.00 | Feb 12, 2024 | Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent. | ||
| CVE-2022-39183 | Med | 0.42 | 6.5 | 0.00 | Jan 12, 2023 | Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors. | ||
| CVE-2021-40693 | Med | 0.42 | 6.5 | 0.01 | Sep 29, 2022 | An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability. | ||
| CVE-2020-25699 | Hig | 0.42 | 7.5 | 0.02 | Nov 19, 2020 | In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed… | ||
| CVE-2020-25698 | Hig | 0.42 | 7.5 | 0.02 | Nov 19, 2020 | Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2… | ||
| CVE-2020-10738 | Hig | 0.42 | 7.5 | 0.03 | May 21, 2020 | A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in… | ||
| CVE-2012-1156 | Hig | 0.42 | 7.5 | 0.02 | Nov 14, 2019 | Moodle before 2.2.2 has users' private files included in course backups | ||
| CVE-2019-10154 | Hig | 0.42 | 7.5 | 0.01 | Jun 26, 2019 | A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations. | ||
| CVE-2019-6970 | Hig | 0.42 | 7.5 | 0.01 | Mar 21, 2019 | Moodle 3.5.x before 3.5.4 allows SSRF. | ||
| CVE-2018-1043 | Med | 0.42 | 6.5 | 0.01 | Jan 22, 2018 | In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames. |
- risk 0.46cvss 8.1epss 0.01
An SQL injection risk was identified in the module list filter within course search.
- risk 0.46cvss 7.1epss 0.01
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
- risk 0.46cvss 8.1epss 0.01
An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
- risk 0.44cvss 6.8epss 0.02
Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
- risk 0.42cvss 7.5epss 0.00
Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.
- risk 0.42cvss 7.5epss 0.01
A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with…
- risk 0.42cvss 7.5epss 0.00
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
- risk 0.42cvss 7.5epss 0.00
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
- risk 0.42cvss 6.5epss 0.00
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
- risk 0.42cvss 7.5epss 0.01
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
- risk 0.42cvss 6.5epss 0.00
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.
- risk 0.42cvss 6.5epss 0.00
Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
- risk 0.42cvss 6.5epss 0.01
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.
- risk 0.42cvss 7.5epss 0.02
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed…
- risk 0.42cvss 7.5epss 0.02
Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2…
- risk 0.42cvss 7.5epss 0.03
A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in…
- risk 0.42cvss 7.5epss 0.02
Moodle before 2.2.2 has users' private files included in course backups
- risk 0.42cvss 7.5epss 0.01
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
- risk 0.42cvss 7.5epss 0.01
Moodle 3.5.x before 3.5.4 allows SSRF.
- risk 0.42cvss 6.5epss 0.01
In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.
Page 4 of 32