Vendor CVEs
Moodle
All CVEs
647 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-14322 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service. | ||
| CVE-2021-32476 | Hig | 0.49 | 7.5 | 0.01 | Mar 11, 2022 | A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected. | ||
| CVE-2020-25630 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2020 | A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and… | ||
| CVE-2012-1170 | Hig | 0.49 | 7.5 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough | ||
| CVE-2012-1155 | Hig | 0.49 | 7.5 | 0.02 | Nov 14, 2019 | Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to | ||
| CVE-2016-7919 | Hig | 0.49 | 7.5 | 0.02 | Oct 28, 2016 | Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting… | ||
| CVE-2024-34001 | Hig | 0.48 | 8.4 | 0.00 | May 31, 2024 | Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk. | ||
| CVE-2016-7038 | Hig | 0.48 | 7.3 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed. | ||
| CVE-2026-26046 | Hig | 0.47 | 7.2 | 0.03 | Feb 21, 2026 | A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an… | ||
| CVE-2021-47857 | Hig | 0.47 | 7.2 | 0.00 | Jan 21, 2026 | Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code… | ||
| CVE-2024-43436 | Hig | 0.47 | 7.2 | 0.01 | Nov 7, 2024 | A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators. | ||
| CVE-2020-1756 | Hig | 0.47 | 7.2 | 0.01 | Aug 16, 2022 | In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool. | ||
| CVE-2021-32474 | Hig | 0.47 | 7.2 | 0.01 | Mar 11, 2022 | An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier… | ||
| CVE-2021-26812 | Med | 0.47 | 6.1 | 0.97 | Apr 14, 2021 | Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application. | ||
| CVE-2021-20187 | Hig | 0.47 | 7.2 | 0.02 | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication. | ||
| CVE-2025-67848 | Hig | 0.46 | 8.1 | 0.00 | Feb 3, 2026 | A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling… | ||
| CVE-2025-3625 | Hig | 0.46 | 7.1 | 0.00 | Apr 25, 2025 | A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA). | ||
| CVE-2025-26533 | Hig | 0.46 | 8.1 | 0.01 | Feb 24, 2025 | An SQL injection risk was identified in the module list filter within course search. | ||
| CVE-2022-40313 | Hig | 0.46 | 7.1 | 0.01 | Sep 30, 2022 | Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load. | ||
| CVE-2018-1137 | Hig | 0.46 | 8.1 | 0.02 | May 25, 2018 | An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack. | ||
| CVE-2025-2202 | Med | 0.45 | — | 0.00 | Mar 17, 2025 | Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email. | ||
| CVE-2025-2201 | Med | 0.45 | — | 0.00 | Mar 17, 2025 | Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as public IP addresses, messages with other users and more. | ||
| CVE-2015-5332 | Med | 0.44 | 6.8 | 0.02 | Feb 22, 2016 | Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature. | ||
| CVE-2025-62399 | Hig | 0.42 | 7.5 | 0.00 | Oct 23, 2025 | Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks. | ||
| CVE-2025-32044 | Hig | 0.42 | 7.5 | 0.01 | Apr 25, 2025 | A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with… | ||
| CVE-2024-45690 | Hig | 0.42 | 7.5 | 0.00 | Nov 20, 2024 | A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts. | ||
| CVE-2024-38275 | Hig | 0.42 | 7.5 | 0.00 | Jun 18, 2024 | The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs. | ||
| CVE-2024-34004 | Med | 0.42 | 6.5 | 0.00 | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include. | ||
| CVE-2024-25978 | Hig | 0.42 | 7.5 | 0.01 | Feb 19, 2024 | Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality. | ||
| CVE-2024-1439 | Med | 0.42 | 6.5 | 0.00 | Feb 12, 2024 | Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent. | ||
| CVE-2022-39183 | Med | 0.42 | 6.5 | 0.00 | Jan 12, 2023 | Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors. | ||
| CVE-2021-40693 | Med | 0.42 | 6.5 | 0.01 | Sep 29, 2022 | An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability. | ||
| CVE-2020-25699 | Hig | 0.42 | 7.5 | 0.02 | Nov 19, 2020 | In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed… | ||
| CVE-2020-25698 | Hig | 0.42 | 7.5 | 0.02 | Nov 19, 2020 | Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2… | ||
| CVE-2020-10738 | Hig | 0.42 | 7.5 | 0.03 | May 21, 2020 | A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in… | ||
| CVE-2012-1156 | Hig | 0.42 | 7.5 | 0.02 | Nov 14, 2019 | Moodle before 2.2.2 has users' private files included in course backups | ||
| CVE-2019-10154 | Hig | 0.42 | 7.5 | 0.01 | Jun 26, 2019 | A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations. | ||
| CVE-2019-6970 | Hig | 0.42 | 7.5 | 0.01 | Mar 21, 2019 | Moodle 3.5.x before 3.5.4 allows SSRF. | ||
| CVE-2018-1043 | Med | 0.42 | 6.5 | 0.01 | Jan 22, 2018 | In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames. | ||
| CVE-2017-2642 | Med | 0.42 | 6.5 | 0.01 | Jul 17, 2017 | Moodle 3.x has user fullname disclosure on the user preferences page. | ||
| CVE-2016-3729 | Med | 0.42 | 6.5 | 0.01 | Apr 20, 2017 | The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator. | ||
| CVE-2015-5267 | Hig | 0.42 | 7.5 | 0.02 | Feb 22, 2016 | lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict… | ||
| CVE-2018-10891 | Hig | 0.41 | 7.3 | 0.02 | Jul 10, 2018 | A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank. | ||
| CVE-2017-7489 | Med | 0.41 | 6.3 | 0.01 | May 15, 2017 | In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link. | ||
| CVE-2015-3272 | Hig | 0.41 | 7.4 | 0.02 | Feb 22, 2016 | Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors… | ||
| CVE-2026-26045 | Hig | 0.40 | 7.2 | 0.01 | Feb 21, 2026 | A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are… | ||
| CVE-2025-67850 | Hig | 0.40 | 7.3 | 0.00 | Feb 3, 2026 | A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users… | ||
| CVE-2025-67849 | Hig | 0.40 | 7.3 | 0.00 | Feb 3, 2026 | A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen,… | ||
| CVE-2025-34032 | Med | 0.40 | 6.1 | 0.01 | Jun 24, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the data parameter in jsmol.php. The application fails to properly sanitize user input before embedding it into the HTTP response, allowing an attacker to execute… | ||
| CVE-2024-34312 | Med | 0.40 | 6.1 | 0.01 | Jun 24, 2024 | Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js. |
- risk 0.49cvss 7.5epss 0.01
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.
- risk 0.49cvss 7.5epss 0.01
A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
- risk 0.49cvss 7.5epss 0.01
A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, which could lead to a denial of service risk. This affects versions 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and…
- risk 0.49cvss 7.5epss 0.01
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
- risk 0.49cvss 7.5epss 0.02
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
- risk 0.49cvss 7.5epss 0.02
Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting…
- risk 0.48cvss 8.4epss 0.00
Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
- risk 0.48cvss 7.3epss 0.01
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
- risk 0.47cvss 7.2epss 0.03
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an…
- risk 0.47cvss 7.2epss 0.00
Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code…
- risk 0.47cvss 7.2epss 0.01
A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.
- risk 0.47cvss 7.2epss 0.01
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.
- risk 0.47cvss 7.2epss 0.01
An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier…
- risk 0.47cvss 6.1epss 0.97
Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application.
- risk 0.47cvss 7.2epss 0.02
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.
- risk 0.46cvss 8.1epss 0.00
A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling…
- risk 0.46cvss 7.1epss 0.00
A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).
- risk 0.46cvss 8.1epss 0.01
An SQL injection risk was identified in the module list filter within course search.
- risk 0.46cvss 7.1epss 0.01
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
- risk 0.46cvss 8.1epss 0.02
An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
- risk 0.45cvss —epss 0.00
Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email.
- risk 0.45cvss —epss 0.00
Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as public IP addresses, messages with other users and more.
- risk 0.44cvss 6.8epss 0.02
Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
- risk 0.42cvss 7.5epss 0.00
Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.
- risk 0.42cvss 7.5epss 0.01
A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with…
- risk 0.42cvss 7.5epss 0.00
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
- risk 0.42cvss 7.5epss 0.00
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
- risk 0.42cvss 6.5epss 0.00
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
- risk 0.42cvss 7.5epss 0.01
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
- risk 0.42cvss 6.5epss 0.00
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.
- risk 0.42cvss 6.5epss 0.00
Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
- risk 0.42cvss 6.5epss 0.01
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.
- risk 0.42cvss 7.5epss 0.02
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed…
- risk 0.42cvss 7.5epss 0.02
Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2…
- risk 0.42cvss 7.5epss 0.03
A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in…
- risk 0.42cvss 7.5epss 0.02
Moodle before 2.2.2 has users' private files included in course backups
- risk 0.42cvss 7.5epss 0.01
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
- risk 0.42cvss 7.5epss 0.01
Moodle 3.5.x before 3.5.4 allows SSRF.
- risk 0.42cvss 6.5epss 0.01
In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.
- risk 0.42cvss 6.5epss 0.01
Moodle 3.x has user fullname disclosure on the user preferences page.
- risk 0.42cvss 6.5epss 0.01
The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.
- risk 0.42cvss 7.5epss 0.02
lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for remote attackers to predict…
- risk 0.41cvss 7.3epss 0.02
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is written into the question bank.
- risk 0.41cvss 6.3epss 0.01
In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.
- risk 0.41cvss 7.4epss 0.02
Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors…
- risk 0.40cvss 7.2epss 0.01
A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are…
- risk 0.40cvss 7.3epss 0.00
A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users…
- risk 0.40cvss 7.3epss 0.00
A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen,…
- risk 0.40cvss 6.1epss 0.01
A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the data parameter in jsmol.php. The application fails to properly sanitize user input before embedding it into the HTTP response, allowing an attacker to execute…
- risk 0.40cvss 6.1epss 0.01
Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.
Page 2 of 13