Moodle
Moodle is a free and open-source learning management system written in PHP and distributed under the GNU General Public License. Moodle is used for blended learning, distance education, flipped classroom and other online learning projects in schools, universities, workplaces and other sectors.
Products
21- 632 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
647| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-36393 | Cri | 0.68 | 9.8 | 0.52 | Mar 6, 2023 | In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. | ||
| CVE-2017-2641 | Cri | 0.68 | 9.8 | 0.15 | Mar 26, 2017 | In Moodle 2.x and 3.x, SQL injection can occur via user preferences. | ||
| CVE-2025-63564 | Cri | 0.64 | 9.8 | 0.01 | Sep 23, 2026 | SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests | ||
| CVE-2021-36394 | Cri | 0.64 | 9.8 | 0.07 | Mar 6, 2023 | In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. | ||
| CVE-2021-36392 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2023 | In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. | ||
| CVE-2022-40315 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2022 | A limited SQL injection risk was identified in the "browse list of users" site administration page. | ||
| CVE-2021-21809 | Cri | 0.64 | 9.1 | 0.24 | Jun 23, 2021 | A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities. | ||
| CVE-2019-15536 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2019 | The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records. | ||
| CVE-2022-0332 | Cri | 0.63 | 9.8 | 0.45 | Jan 25, 2022 | A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data. | ||
| CVE-2025-2200 | Cri | 0.60 | — | 0.00 | Mar 17, 2025 | SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint… | ||
| CVE-2025-2199 | Cri | 0.60 | — | 0.00 | Mar 17, 2025 | SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query in ‘searchActionsToUpdate’,… | ||
| CVE-2019-14880 | Cri | 0.59 | 9.1 | 0.01 | Mar 31, 2020 | A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise. | ||
| CVE-2025-60507 | Hig | 0.58 | 8.9 | 0.00 | Oct 21, 2025 | Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users… | ||
| CVE-2016-9187 | Hig | 0.58 | 8.8 | 0.04 | Nov 4, 2016 | Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | ||
| CVE-2016-9186 | Hig | 0.58 | 8.8 | 0.04 | Nov 4, 2016 | Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | ||
| CVE-2025-67847 | Hig | 0.57 | 8.8 | 0.01 | Jan 23, 2026 | A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation… | ||
| CVE-2023-28333 | Cri | 0.57 | 9.8 | 0.01 | Mar 23, 2023 | The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS). | ||
| CVE-2022-30600 | Cri | 0.57 | 9.8 | 0.05 | May 18, 2022 | A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed. | ||
| CVE-2022-30599 | Cri | 0.57 | 9.8 | 0.01 | May 18, 2022 | A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria. | ||
| CVE-2021-3943 | Cri | 0.57 | 9.8 | 0.02 | Nov 22, 2021 | A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified. |
- risk 0.68cvss 9.8epss 0.52
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
- risk 0.68cvss 9.8epss 0.15
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests
- risk 0.64cvss 9.8epss 0.07
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
- risk 0.64cvss 9.8epss 0.01
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
- risk 0.64cvss 9.8epss 0.01
A limited SQL injection risk was identified in the "browse list of users" site administration page.
- risk 0.64cvss 9.1epss 0.24
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
- risk 0.64cvss 9.8epss 0.01
The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
- risk 0.63cvss 9.8epss 0.45
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
- risk 0.60cvss —epss 0.00
SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint…
- risk 0.60cvss —epss 0.00
SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query in ‘searchActionsToUpdate’,…
- risk 0.59cvss 9.1epss 0.01
A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.
- risk 0.58cvss 8.9epss 0.00
Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users…
- risk 0.58cvss 8.8epss 0.04
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
- risk 0.58cvss 8.8epss 0.04
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
- risk 0.57cvss 8.8epss 0.01
A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation…
- risk 0.57cvss 9.8epss 0.01
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).
- risk 0.57cvss 9.8epss 0.05
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
- risk 0.57cvss 9.8epss 0.01
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
- risk 0.57cvss 9.8epss 0.02
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.