VYPR

Vendor CVEs

Moodle

All CVEs

647 total · sorted by risk
  • CVE-2020-14322HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.

  • CVE-2021-32476HigMar 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.

  • CVE-2020-25630HigDec 8, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and…

  • CVE-2012-1170HigNov 14, 2019
    risk 0.49cvss 7.5epss 0.01

    Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough

  • CVE-2012-1155HigNov 14, 2019
    risk 0.49cvss 7.5epss 0.02

    Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to

  • CVE-2016-7919HigOct 28, 2016
    risk 0.49cvss 7.5epss 0.02

    Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting…

  • CVE-2024-34001HigMay 31, 2024
    risk 0.48cvss 8.4epss 0.00

    Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

  • CVE-2016-7038HigJan 20, 2017
    risk 0.48cvss 7.3epss 0.01

    In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

  • CVE-2026-26046HigFeb 21, 2026
    risk 0.47cvss 7.2epss 0.03

    A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an…

  • CVE-2021-47857HigJan 21, 2026
    risk 0.47cvss 7.2epss 0.00

    Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code…

  • CVE-2024-43436HigNov 7, 2024
    risk 0.47cvss 7.2epss 0.01

    A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.

  • CVE-2020-1756HigAug 16, 2022
    risk 0.47cvss 7.2epss 0.01

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

  • CVE-2021-32474HigMar 11, 2022
    risk 0.47cvss 7.2epss 0.01

    An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier…

  • CVE-2021-26812MedApr 14, 2021
    risk 0.47cvss 6.1epss 0.97

    Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application.

  • CVE-2021-20187HigJan 28, 2021
    risk 0.47cvss 7.2epss 0.02

    It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.

  • CVE-2025-67848HigFeb 3, 2026
    risk 0.46cvss 8.1epss 0.00

    A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling…

  • CVE-2025-3625HigApr 25, 2025
    risk 0.46cvss 7.1epss 0.00

    A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).

  • CVE-2025-26533HigFeb 24, 2025
    risk 0.46cvss 8.1epss 0.01

    An SQL injection risk was identified in the module list filter within course search.

  • CVE-2022-40313HigSep 30, 2022
    risk 0.46cvss 7.1epss 0.01

    Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

  • CVE-2018-1137HigMay 25, 2018
    risk 0.46cvss 8.1epss 0.02

    An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.

  • CVE-2025-2202MedMar 17, 2025
    risk 0.45cvss —epss 0.00

    Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email.

  • CVE-2025-2201MedMar 17, 2025
    risk 0.45cvss —epss 0.00

    Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as public IP addresses, messages with other users and more.

  • CVE-2015-5332MedFeb 22, 2016
    risk 0.44cvss 6.8epss 0.02

    Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.

  • CVE-2025-62399HigOct 23, 2025
    risk 0.42cvss 7.5epss 0.00

    Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

  • CVE-2025-32044HigApr 25, 2025
    risk 0.42cvss 7.5epss 0.01

    A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with…

  • CVE-2024-45690HigNov 20, 2024
    risk 0.42cvss 7.5epss 0.00

    A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

  • CVE-2024-38275HigJun 18, 2024
    risk 0.42cvss 7.5epss 0.00

    The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

  • CVE-2024-34004MedMay 31, 2024
    risk 0.42cvss 6.5epss 0.00

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

  • CVE-2024-25978HigFeb 19, 2024
    risk 0.42cvss 7.5epss 0.01

    Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

  • CVE-2024-1439MedFeb 12, 2024
    risk 0.42cvss 6.5epss 0.00

    Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

  • CVE-2022-39183MedJan 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.

  • CVE-2021-40693MedSep 29, 2022
    risk 0.42cvss 6.5epss 0.01

    An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.

  • CVE-2020-25699HigNov 19, 2020
    risk 0.42cvss 7.5epss 0.02

    In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed…

  • CVE-2020-25698HigNov 19, 2020
    risk 0.42cvss 7.5epss 0.02

    Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2…

  • CVE-2020-10738HigMay 21, 2020
    risk 0.42cvss 7.5epss 0.03

    A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in…

  • CVE-2012-1156HigNov 14, 2019
    risk 0.42cvss 7.5epss 0.02

    Moodle before 2.2.2 has users' private files included in course backups

  • CVE-2019-10154HigJun 26, 2019
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

  • CVE-2019-6970HigMar 21, 2019
    risk 0.42cvss 7.5epss 0.01

    Moodle 3.5.x before 3.5.4 allows SSRF.

  • CVE-2018-1043MedJan 22, 2018
    risk 0.42cvss 6.5epss 0.01

    In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.

  • CVE-2017-2642MedJul 17, 2017
    risk 0.42cvss 6.5epss 0.01

    Moodle 3.x has user fullname disclosure on the user preferences page.

  • CVE-2016-3729MedApr 20, 2017
    risk 0.42cvss 6.5epss 0.01

    The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.

  • CVE-2015-5267HigFeb 22, 2016
    risk 0.42cvss 7.5epss 0.02

    lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict…

  • CVE-2018-10891HigJul 10, 2018
    risk 0.41cvss 7.3epss 0.02

    A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.

  • CVE-2017-7489MedMay 15, 2017
    risk 0.41cvss 6.3epss 0.01

    In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.

  • CVE-2015-3272HigFeb 22, 2016
    risk 0.41cvss 7.4epss 0.02

    Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors…

  • CVE-2026-26045HigFeb 21, 2026
    risk 0.40cvss 7.2epss 0.01

    A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are…

  • CVE-2025-67850HigFeb 3, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users…

  • CVE-2025-67849HigFeb 3, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen,…

  • CVE-2025-34032MedJun 24, 2025
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the data parameter in jsmol.php. The application fails to properly sanitize user input before embedding it into the HTTP response, allowing an attacker to execute…

  • CVE-2024-34312MedJun 24, 2024
    risk 0.40cvss 6.1epss 0.01

    Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.

Page 2 of 13