VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2017-2578MedJan 20, 2017
    risk 0.40cvss 6.1epss 0.01

    In Moodle 3.x, there is XSS in the assignment submission page.

  • CVE-2016-9188MedNov 4, 2016
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.

  • CVE-2016-0725MedFeb 22, 2016
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted search…

  • CVE-2018-1042MedJan 22, 2018
    risk 0.39cvss 6.5epss 0.16

    Moodle 3.x has Server Side Request Forgery in the filepicker.

  • CVE-2015-5266MedFeb 22, 2016
    risk 0.37cvss 6.8epss 0.01

    The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing…

  • CVE-2024-37674MedJun 20, 2024
    risk 0.36cvss 5.5epss 0.01

    Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.

  • CVE-2023-30943MedMay 2, 2023
    risk 0.36cvss 6.5epss 0.07

    The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.

  • CVE-2026-26047MedFeb 21, 2026
    risk 0.35cvss 6.5epss 0.00

    A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this…

  • CVE-2024-45689MedNov 20, 2024
    risk 0.35cvss 6.5epss 0.00

    A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.

  • CVE-2024-34005MedMay 31, 2024
    risk 0.35cvss 6.5epss 0.00

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

  • CVE-2024-28593MedMar 22, 2024
    risk 0.35cvss 5.4epss 0.01

    The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do…

  • CVE-2023-5550MedNov 9, 2023
    risk 0.35cvss 6.5epss 0.01

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.

  • CVE-2023-5544MedNov 9, 2023
    risk 0.35cvss 6.5epss 0.01

    Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.

  • CVE-2023-46858MedOct 29, 2023
    risk 0.35cvss 5.4epss 0.01

    Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content,…

  • CVE-2021-27131MedMay 16, 2023
    risk 0.35cvss 5.4epss 0.01

    Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" via "Header and Footer" parameter in /admin/settings.php. This vulnerability is leading an attacker to steal admin and all user…

  • CVE-2023-28330MedMar 23, 2023
    risk 0.35cvss 6.5epss 0.01

    Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

  • CVE-2021-36399MedMar 6, 2023
    risk 0.35cvss 5.4epss 0.01

    In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.

  • CVE-2021-36398MedMar 6, 2023
    risk 0.35cvss 5.4epss 0.01

    In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.

  • CVE-2021-36568MedSep 13, 2022
    risk 0.35cvss 5.4epss 0.01

    In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects…

  • CVE-2021-32475MedMar 11, 2022
    risk 0.35cvss 5.4epss 0.01

    ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.

Page 6 of 32