VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2016-5012MedJan 20, 2017
    risk 0.35cvss 5.3epss 0.01

    In Moodle 3.x, glossary search displays entries without checking user permissions to view them.

  • CVE-2025-62397MedOct 23, 2025
    risk 0.34cvss 5.3epss 0.00

    The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

  • CVE-2021-36403MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.

  • CVE-2021-36402MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.

  • CVE-2021-36400MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.

  • CVE-2021-36397MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, insufficient capability checks meant message deletions were not limited to the current user.

  • CVE-2020-1755MedAug 16, 2022
    risk 0.34cvss 5.3epss 0.01

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

  • CVE-2022-50943MedMay 10, 2026
    risk 0.33cvss 6.1epss 0.00

    Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary…

  • CVE-2025-67851MedFeb 3, 2026
    risk 0.33cvss 6.1epss 0.00

    A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute.…

  • CVE-2024-33997MedMay 31, 2024
    risk 0.33cvss 6.1epss 0.00

    Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

  • CVE-2023-28332MedMar 23, 2023
    risk 0.33cvss 6.1epss 0.01

    If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.

  • CVE-2023-28331MedMar 23, 2023
    risk 0.33cvss 6.1epss 0.01

    Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.

  • CVE-2020-14320MedAug 16, 2022
    risk 0.33cvss 6.1epss 0.01

    In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.

  • CVE-2022-35652MedJul 25, 2022
    risk 0.33cvss 6.1epss 0.01

    An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful…

  • CVE-2021-32478MedMar 11, 2022
    risk 0.33cvss 6.1epss 0.01

    The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.

  • CVE-2020-25628MedDec 8, 2020
    risk 0.33cvss 6.1epss 0.01

    The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

  • CVE-2020-25702MedNov 19, 2020
    risk 0.33cvss 6.1epss 0.01

    In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

  • CVE-2019-14881MedMar 18, 2020
    risk 0.33cvss 6.1epss 0.01

    A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

  • CVE-2017-12156MedSep 18, 2017
    risk 0.33cvss 6.1epss 0.01

    Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

  • CVE-2017-2644MedMar 26, 2017
    risk 0.33cvss 6.1epss 0.01

    In Moodle 3.x, XSS can occur via evidence of prior learning.

Page 8 of 32