VYPR

Moodle

by Moodle

Source repositories

CVEs (632)

  • CVE-2016-2153MedMay 22, 2016
    risk 0.33cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field…

  • CVE-2016-2152MedMay 22, 2016
    risk 0.33cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field.

  • CVE-2015-5337MedFeb 22, 2016
    risk 0.33cvss 6.1epss 0.01

    Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.

  • CVE-2015-3275MedFeb 22, 2016
    risk 0.33cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1)…

  • CVE-2015-3274MedFeb 22, 2016
    risk 0.33cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an…

  • CVE-2021-40694MedSep 29, 2022
    risk 0.32cvss 4.9epss 0.01

    Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.

  • CVE-2021-36401MedMar 6, 2023
    risk 0.31cvss 4.8epss 0.01

    In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.

  • CVE-2023-30944MedMay 2, 2023
    risk 0.29cvss 5.6epss 0.01

    The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the…

  • CVE-2025-67856MedFeb 3, 2026
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to,…

  • CVE-2025-67855MedFeb 3, 2026
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This vulnerability arises from insufficient sanitization of URL parameters, allowing attackers to inject malicious scripts through…

  • CVE-2025-62401MedOct 23, 2025
    risk 0.28cvss 5.4epss 0.00

    An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.

  • CVE-2025-62398MedOct 23, 2025
    risk 0.28cvss 5.4epss 0.00

    A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

  • CVE-2025-62395MedOct 23, 2025
    risk 0.28cvss 4.3epss 0.00

    A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

  • CVE-2025-60511MedOct 21, 2025
    risk 0.28cvss 4.3epss 0.00

    Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in /blocks/openai_chat/api/completion.php. An authenticated student can impersonate another user's…

  • CVE-2025-3644MedApr 25, 2025
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.

  • CVE-2025-3643MedApr 25, 2025
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

  • CVE-2025-3627MedApr 25, 2025
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).

  • CVE-2024-45691MedNov 20, 2024
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.

  • CVE-2024-48901MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.

  • CVE-2024-48898MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.

Page 9 of 32