VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2017-2642MedJul 17, 2017
    risk 0.42cvss 6.5epss 0.01

    Moodle 3.x has user fullname disclosure on the user preferences page.

  • CVE-2016-3729MedApr 20, 2017
    risk 0.42cvss 6.5epss 0.01

    The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.

  • CVE-2015-5267HigFeb 22, 2016
    risk 0.42cvss 7.5epss 0.02

    lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict…

  • CVE-2018-10891HigJul 10, 2018
    risk 0.41cvss 7.3epss 0.02

    A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.

  • CVE-2017-7489MedMay 15, 2017
    risk 0.41cvss 6.3epss 0.02

    In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.

  • CVE-2015-3272HigFeb 22, 2016
    risk 0.41cvss 7.4epss 0.02

    Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors…

  • CVE-2026-26045HigFeb 21, 2026
    risk 0.40cvss 7.2epss 0.01

    A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are…

  • CVE-2025-67850HigFeb 3, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users…

  • CVE-2025-67849HigFeb 3, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen,…

  • CVE-2024-38274MedJun 18, 2024
    risk 0.40cvss 6.1epss 0.00

    Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

  • CVE-2024-29374MedMar 21, 2024
    risk 0.40cvss 6.1epss 0.01

    A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

  • CVE-2021-43558MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.

  • CVE-2019-14831MedMar 19, 2021
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode was set to "forced subscription", the…

  • CVE-2019-14830MedMar 19, 2021
    risk 0.40cvss 6.1epss 0.03

    A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does…

  • CVE-2020-25627MedDec 9, 2020
    risk 0.40cvss 6.1epss 0.04

    The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

  • CVE-2020-25631MedDec 8, 2020
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.

  • CVE-2019-14884MedMar 18, 2020
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

  • CVE-2019-14882MedMar 18, 2020
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

  • CVE-2017-2645MedMar 26, 2017
    risk 0.40cvss 6.1epss 0.01

    In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.

  • CVE-2017-5945MedFeb 10, 2017
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in the PoodLL Filter plugin through 3.0.20 for Moodle. The vulnerability exists due to insufficient filtration of user-supplied data in the "poodll_audio_url" HTTP GET parameter passed to the "filter_poodll_moodle32_2016112802/poodll/mp3recorderskins/brazi…

Page 5 of 32