VYPR

Vendor CVEs

Moodle

All CVEs

647 total · sorted by risk
  • CVE-2021-36393CriMar 6, 2023
    risk 0.68cvss 9.8epss 0.52

    In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

  • CVE-2017-2641CriMar 26, 2017
    risk 0.68cvss 9.8epss 0.15

    In Moodle 2.x and 3.x, SQL injection can occur via user preferences.

  • CVE-2025-63564CriSep 23, 2026
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests

  • CVE-2021-36394CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.07

    In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

  • CVE-2021-36392CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.

  • CVE-2022-40315CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    A limited SQL injection risk was identified in the "browse list of users" site administration page.

  • CVE-2021-21809CriJun 23, 2021
    risk 0.64cvss 9.1epss 0.24

    A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.

  • CVE-2019-15536CriAug 23, 2019
    risk 0.64cvss 9.8epss 0.01

    The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.

  • CVE-2022-0332CriJan 25, 2022
    risk 0.63cvss 9.8epss 0.45

    A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.

  • CVE-2025-2200CriMar 17, 2025
    risk 0.60cvss —epss 0.00

    SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint…

  • CVE-2025-2199CriMar 17, 2025
    risk 0.60cvss —epss 0.00

    SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query in ‘searchActionsToUpdate’,…

  • CVE-2019-14880CriMar 31, 2020
    risk 0.59cvss 9.1epss 0.01

    A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify users' email address changes require additional verification during sign-up to reduce the risk of account compromise.

  • CVE-2025-60507HigOct 21, 2025
    risk 0.58cvss 8.9epss 0.00

    Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users…

  • CVE-2016-9187HigNov 4, 2016
    risk 0.58cvss 8.8epss 0.04

    Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

  • CVE-2016-9186HigNov 4, 2016
    risk 0.58cvss 8.8epss 0.04

    Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

  • CVE-2025-67847HigJan 23, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation…

  • CVE-2023-28333CriMar 23, 2023
    risk 0.57cvss 9.8epss 0.01

    The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

  • CVE-2022-30600CriMay 18, 2022
    risk 0.57cvss 9.8epss 0.05

    A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

  • CVE-2022-30599CriMay 18, 2022
    risk 0.57cvss 9.8epss 0.01

    A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.

  • CVE-2021-3943CriNov 22, 2021
    risk 0.57cvss 9.8epss 0.02

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.

  • CVE-2020-25629HigDec 8, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some site administration capabilities by "logging in as" a System manager. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5…

  • CVE-2018-1133HigMay 25, 2018
    risk 0.56cvss 8.8epss 0.32

    An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.

  • CVE-2026-30884CriMar 18, 2026
    risk 0.55cvss 9.6epss 0.00

    mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. Prior to versions 4.4.9 and 5.0.3, a teacher who holds `mod/customcert:manage` in any single course can read and silently overwrite…

  • CVE-2020-14321HigAug 16, 2022
    risk 0.54cvss 8.8epss 0.16

    In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.

  • CVE-2024-43434HigNov 7, 2024
    risk 0.53cvss 8.1epss 0.01

    The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.

  • CVE-2020-1692HigFeb 17, 2020
    risk 0.53cvss 8.1epss 0.01

    Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

  • CVE-2012-1168HigNov 14, 2019
    risk 0.53cvss 8.2epss 0.02

    Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

  • CVE-2018-1082HigApr 4, 2018
    risk 0.53cvss 8.1epss 0.02

    A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site.

  • CVE-2018-14630HigSep 17, 2018
    risk 0.51cvss 8.8epss 0.04

    moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within…

  • CVE-2025-3642HigApr 25, 2025
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.

  • CVE-2025-3641HigApr 25, 2025
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.

  • CVE-2025-3638HigApr 25, 2025
    risk 0.50cvss 8.8epss 0.00

    A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.

  • CVE-2024-38276HigJun 18, 2024
    risk 0.50cvss 8.8epss 0.00

    Incorrect CSRF token checks resulted in multiple CSRF risks.

  • CVE-2024-34008HigMay 31, 2024
    risk 0.50cvss 8.8epss 0.00

    Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.

  • CVE-2023-28335HigMar 23, 2023
    risk 0.50cvss 8.8epss 0.00

    The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.

  • CVE-2023-28329HigMar 23, 2023
    risk 0.50cvss 8.8epss 0.01

    Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

  • CVE-2022-0983HigMar 25, 2022
    risk 0.50cvss 8.8epss 0.01

    An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

  • CVE-2022-0335HigJan 25, 2022
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.

  • CVE-2021-43559HigNov 22, 2021
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

  • CVE-2019-10186HigJul 31, 2019
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.

  • CVE-2019-3849HigMar 26, 2019
    risk 0.50cvss 8.8epss 0.01

    A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.

  • CVE-2018-14631HigSep 17, 2018
    risk 0.50cvss 8.8epss 0.02

    moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search results of a blog were insufficiently filtered, which could result in reflected…

  • CVE-2016-3734HigApr 20, 2017
    risk 0.50cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.

  • CVE-2016-2157HigMay 22, 2016
    risk 0.50cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to hijack the authentication of administrators for requests…

  • CVE-2015-5338HigFeb 22, 2016
    risk 0.50cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote attackers to hijack the authentication of arbitrary users for requests to (1)…

  • CVE-2025-67853HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.

  • CVE-2025-34031HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.03

    A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read arbitrary files from…

  • CVE-2024-43440HigNov 7, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in moodle. A local file may include risks when restoring block backups.

  • CVE-2024-43438HigNov 7, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.

  • CVE-2024-43431HigNov 7, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.

Page 1 of 13