VYPR
Vendor

Moodle

Moodle is a free and open-source learning management system written in PHP and distributed under the GNU General Public License. Moodle is used for blended learning, distance education, flipped classroom and other online learning projects in schools, universities, workplaces and other sectors.

Founded 2002
Products
20
CVEs
646
Across products
653
Status
Private

Products

20

Recent CVEs

646
View all 646 CVEs →
  • CVE-2021-36393CriMar 6, 2023
    risk 0.68cvss 9.8epss 0.52

    In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

  • CVE-2017-2641CriMar 26, 2017
    risk 0.68cvss 9.8epss 0.15

    In Moodle 2.x and 3.x, SQL injection can occur via user preferences.

  • CVE-2021-36394CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.07

    In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

  • CVE-2021-36392CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.

  • CVE-2022-40315CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    A limited SQL injection risk was identified in the "browse list of users" site administration page.

  • CVE-2021-21809CriJun 23, 2021
    risk 0.64cvss 9.1epss 0.24

    A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.

  • CVE-2022-0332CriJan 25, 2022
    risk 0.63cvss 9.8epss 0.45

    A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.

  • CVE-2018-1133HigMay 25, 2018
    risk 0.63cvss 8.8epss 0.32

    An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.

  • CVE-2025-2200CriMar 17, 2025
    risk 0.60cvss epss 0.00

    SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint…

  • CVE-2025-2199CriMar 17, 2025
    risk 0.60cvss epss 0.00

    SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query in ‘searchActionsToUpdate’,…

  • CVE-2019-14880CriMar 31, 2020
    risk 0.59cvss 9.1epss 0.01

    A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

  • CVE-2025-60507HigOct 21, 2025
    risk 0.58cvss 8.9epss 0.00

    Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users…

  • CVE-2016-9187HigNov 4, 2016
    risk 0.58cvss 8.8epss 0.04

    Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

  • CVE-2016-9186HigNov 4, 2016
    risk 0.58cvss 8.8epss 0.04

    Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

  • CVE-2025-67847HigJan 23, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation…

  • CVE-2023-28333CriMar 23, 2023
    risk 0.57cvss 9.8epss 0.01

    The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

  • CVE-2022-30600CriMay 18, 2022
    risk 0.57cvss 9.8epss 0.05

    A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

  • CVE-2022-30599CriMay 18, 2022
    risk 0.57cvss 9.8epss 0.01

    A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.

  • CVE-2021-3943CriNov 22, 2021
    risk 0.57cvss 9.8epss 0.02

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.

  • CVE-2020-25629HigDec 8, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5…