Moodle
by Moodle
Source repositories
CVEs (632)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-2578 | Med | 0.40 | 6.1 | 0.01 | Jan 20, 2017 | In Moodle 3.x, there is XSS in the assignment submission page. | ||
| CVE-2016-9188 | Med | 0.40 | 6.1 | 0.02 | Nov 4, 2016 | Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters. | ||
| CVE-2016-0725 | Med | 0.40 | 6.1 | 0.02 | Feb 22, 2016 | Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted search… | ||
| CVE-2018-1042 | Med | 0.39 | 6.5 | 0.16 | Jan 22, 2018 | Moodle 3.x has Server Side Request Forgery in the filepicker. | ||
| CVE-2015-5266 | Med | 0.37 | 6.8 | 0.01 | Feb 22, 2016 | The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing… | ||
| CVE-2024-37674 | Med | 0.36 | 5.5 | 0.01 | Jun 20, 2024 | Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity. | ||
| CVE-2023-30943 | Med | 0.36 | 6.5 | 0.07 | May 2, 2023 | The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system. | ||
| CVE-2026-26047 | Med | 0.35 | 6.5 | 0.00 | Feb 21, 2026 | A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this… | ||
| CVE-2024-45689 | Med | 0.35 | 6.5 | 0.00 | Nov 20, 2024 | A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access. | ||
| CVE-2024-34005 | Med | 0.35 | 6.5 | 0.00 | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include. | ||
| CVE-2024-28593 | Med | 0.35 | 5.4 | 0.01 | Mar 22, 2024 | The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do… | ||
| CVE-2023-5550 | Med | 0.35 | 6.5 | 0.01 | Nov 9, 2023 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution. | ||
| CVE-2023-5544 | Med | 0.35 | 6.5 | 0.01 | Nov 9, 2023 | Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk. | ||
| CVE-2023-46858 | Med | 0.35 | 5.4 | 0.01 | Oct 29, 2023 | Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content,… | ||
| CVE-2021-27131 | Med | 0.35 | 5.4 | 0.01 | May 16, 2023 | Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" via "Header and Footer" parameter in /admin/settings.php. This vulnerability is leading an attacker to steal admin and all user… | ||
| CVE-2023-28330 | Med | 0.35 | 6.5 | 0.01 | Mar 23, 2023 | Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default. | ||
| CVE-2021-36399 | Med | 0.35 | 5.4 | 0.01 | Mar 6, 2023 | In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk. | ||
| CVE-2021-36398 | Med | 0.35 | 5.4 | 0.01 | Mar 6, 2023 | In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk. | ||
| CVE-2021-36568 | Med | 0.35 | 5.4 | 0.01 | Sep 13, 2022 | In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects… | ||
| CVE-2021-32475 | Med | 0.35 | 5.4 | 0.01 | Mar 11, 2022 | ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected. |
- risk 0.40cvss 6.1epss 0.01
In Moodle 3.x, there is XSS in the assignment submission page.
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted search…
- risk 0.39cvss 6.5epss 0.16
Moodle 3.x has Server Side Request Forgery in the filepicker.
- risk 0.37cvss 6.8epss 0.01
The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing…
- risk 0.36cvss 5.5epss 0.01
Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.
- risk 0.36cvss 6.5epss 0.07
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
- risk 0.35cvss 6.5epss 0.00
A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this…
- risk 0.35cvss 6.5epss 0.00
A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
- risk 0.35cvss 6.5epss 0.00
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
- risk 0.35cvss 5.4epss 0.01
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do…
- risk 0.35cvss 6.5epss 0.01
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
- risk 0.35cvss 6.5epss 0.01
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
- risk 0.35cvss 5.4epss 0.01
Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content,…
- risk 0.35cvss 5.4epss 0.01
Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" via "Header and Footer" parameter in /admin/settings.php. This vulnerability is leading an attacker to steal admin and all user…
- risk 0.35cvss 6.5epss 0.01
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
- risk 0.35cvss 5.4epss 0.01
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
- risk 0.35cvss 5.4epss 0.01
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
- risk 0.35cvss 5.4epss 0.01
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects…
- risk 0.35cvss 5.4epss 0.01
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
Page 6 of 32