Moodle
by Moodle
Source repositories
CVEs (632)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-5012 | Med | 0.35 | 5.3 | 0.01 | Jan 20, 2017 | In Moodle 3.x, glossary search displays entries without checking user permissions to view them. | ||
| CVE-2025-62397 | Med | 0.34 | 5.3 | 0.00 | Oct 23, 2025 | The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance. | ||
| CVE-2021-36403 | Med | 0.34 | 5.3 | 0.01 | Mar 6, 2023 | In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk. | ||
| CVE-2021-36402 | Med | 0.34 | 5.3 | 0.01 | Mar 6, 2023 | In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk. | ||
| CVE-2021-36400 | Med | 0.34 | 5.3 | 0.01 | Mar 6, 2023 | In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. | ||
| CVE-2021-36397 | Med | 0.34 | 5.3 | 0.01 | Mar 6, 2023 | In Moodle, insufficient capability checks meant message deletions were not limited to the current user. | ||
| CVE-2020-1755 | Med | 0.34 | 5.3 | 0.01 | Aug 16, 2022 | In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks. | ||
| CVE-2022-50943 | Med | 0.33 | 6.1 | 0.00 | May 10, 2026 | Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary… | ||
| CVE-2025-67851 | Med | 0.33 | 6.1 | 0.00 | Feb 3, 2026 | A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute.… | ||
| CVE-2024-33997 | Med | 0.33 | 6.1 | 0.00 | May 31, 2024 | Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation. | ||
| CVE-2023-28332 | Med | 0.33 | 6.1 | 0.01 | Mar 23, 2023 | If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk. | ||
| CVE-2023-28331 | Med | 0.33 | 6.1 | 0.01 | Mar 23, 2023 | Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk. | ||
| CVE-2020-14320 | Med | 0.33 | 6.1 | 0.01 | Aug 16, 2022 | In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk. | ||
| CVE-2022-35652 | Med | 0.33 | 6.1 | 0.01 | Jul 25, 2022 | An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful… | ||
| CVE-2021-32478 | Med | 0.33 | 6.1 | 0.01 | Mar 11, 2022 | The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected. | ||
| CVE-2020-25628 | Med | 0.33 | 6.1 | 0.01 | Dec 8, 2020 | The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14. | ||
| CVE-2020-25702 | Med | 0.33 | 6.1 | 0.01 | Nov 19, 2020 | In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10. | ||
| CVE-2019-14881 | Med | 0.33 | 6.1 | 0.01 | Mar 18, 2020 | A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed. | ||
| CVE-2017-12156 | Med | 0.33 | 6.1 | 0.01 | Sep 18, 2017 | Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback. | ||
| CVE-2017-2644 | Med | 0.33 | 6.1 | 0.01 | Mar 26, 2017 | In Moodle 3.x, XSS can occur via evidence of prior learning. |
- risk 0.35cvss 5.3epss 0.01
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
- risk 0.34cvss 5.3epss 0.00
The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.
- risk 0.34cvss 5.3epss 0.01
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
- risk 0.34cvss 5.3epss 0.01
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.
- risk 0.34cvss 5.3epss 0.01
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
- risk 0.34cvss 5.3epss 0.01
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
- risk 0.34cvss 5.3epss 0.01
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
- risk 0.33cvss 6.1epss 0.00
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary…
- risk 0.33cvss 6.1epss 0.00
A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute.…
- risk 0.33cvss 6.1epss 0.00
Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.
- risk 0.33cvss 6.1epss 0.01
If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.
- risk 0.33cvss 6.1epss 0.01
Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
- risk 0.33cvss 6.1epss 0.01
In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.
- risk 0.33cvss 6.1epss 0.01
An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful…
- risk 0.33cvss 6.1epss 0.01
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.
- risk 0.33cvss 6.1epss 0.01
The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.
- risk 0.33cvss 6.1epss 0.01
In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.
- risk 0.33cvss 6.1epss 0.01
A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.
- risk 0.33cvss 6.1epss 0.01
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
- risk 0.33cvss 6.1epss 0.01
In Moodle 3.x, XSS can occur via evidence of prior learning.
Page 8 of 32