VYPR

Vendor CVEs

Moodle

All CVEs

647 total · sorted by risk
  • CVE-2026-26045HigFeb 21, 2026
    risk 0.40cvss 7.2epss 0.01

    A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are…

  • CVE-2025-67850HigFeb 3, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users…

  • CVE-2025-67849HigFeb 3, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen,…

  • CVE-2025-34032MedJun 24, 2025
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the data parameter in jsmol.php. The application fails to properly sanitize user input before embedding it into the HTTP response, allowing an attacker to execute…

  • CVE-2024-34312MedJun 24, 2024
    risk 0.40cvss 6.1epss 0.01

    Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.

  • CVE-2024-38274MedJun 18, 2024
    risk 0.40cvss 6.1epss 0.00

    Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

  • CVE-2024-29374MedMar 21, 2024
    risk 0.40cvss 6.1epss 0.01

    A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

  • CVE-2021-43558MedNov 22, 2021
    risk 0.40cvss 6.1epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.

  • CVE-2019-14827MedMay 17, 2021
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another…

  • CVE-2019-14831MedMar 19, 2021
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode was set to "forced subscription", the…

  • CVE-2019-14830MedMar 19, 2021
    risk 0.40cvss 6.1epss 0.03

    A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does…

  • CVE-2020-25627MedDec 9, 2020
    risk 0.40cvss 6.1epss 0.04

    The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

  • CVE-2020-25631MedDec 8, 2020
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title, which was not escaped on the "Add new chapter" page. This is fixed in 3.9.2, 3.8.5 and 3.7.8.

  • CVE-2019-14884MedMar 18, 2020
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.

  • CVE-2019-14882MedMar 18, 2020
    risk 0.40cvss 6.1epss 0.01

    A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

  • CVE-2018-1042MedJan 22, 2018
    risk 0.40cvss 6.5epss 0.17

    Moodle 3.x has Server Side Request Forgery in the filepicker.

  • CVE-2017-2645MedMar 26, 2017
    risk 0.40cvss 6.1epss 0.01

    In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.

  • CVE-2017-5945MedFeb 10, 2017
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in the PoodLL Filter plugin through 3.0.20 for Moodle. The vulnerability exists due to insufficient filtration of user-supplied data in the "poodll_audio_url" HTTP GET parameter passed to the "filter_poodll_moodle32_2016112802/poodll/mp3recorderskins/brazi…

  • CVE-2017-2578MedJan 20, 2017
    risk 0.40cvss 6.1epss 0.01

    In Moodle 3.x, there is XSS in the assignment submission page.

  • CVE-2016-9188MedNov 4, 2016
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.

  • CVE-2016-0725MedFeb 22, 2016
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted search…

  • CVE-2015-5266MedFeb 22, 2016
    risk 0.37cvss 6.8epss 0.02

    The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager privileges in opportunistic circumstances by leveraging incorrect role processing…

  • CVE-2024-37674MedJun 20, 2024
    risk 0.36cvss 5.5epss 0.01

    Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.

  • CVE-2023-30943MedMay 2, 2023
    risk 0.36cvss 6.5epss 0.07

    The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.

  • CVE-2026-26047MedFeb 21, 2026
    risk 0.35cvss 6.5epss 0.01

    A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this…

  • CVE-2025-60506MedOct 21, 2025
    risk 0.35cvss 5.4epss 0.00

    Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An attacker with a low-privileged account (e.g., Student) can inject arbitrary JavaScript payloads into a comment. When any other user (Student, Teacher, or…

  • CVE-2024-45689MedNov 20, 2024
    risk 0.35cvss 6.5epss 0.00

    A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.

  • CVE-2024-34005MedMay 31, 2024
    risk 0.35cvss 6.5epss 0.00

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

  • CVE-2024-28593MedMar 22, 2024
    risk 0.35cvss 5.4epss 0.01

    The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do…

  • CVE-2023-5550MedNov 9, 2023
    risk 0.35cvss 6.5epss 0.01

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.

  • CVE-2023-5544MedNov 9, 2023
    risk 0.35cvss 6.5epss 0.01

    Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.

  • CVE-2023-46858MedOct 29, 2023
    risk 0.35cvss 5.4epss 0.01

    Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content,…

  • CVE-2021-27131MedMay 16, 2023
    risk 0.35cvss 5.4epss 0.01

    Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" via "Header and Footer" parameter in /admin/settings.php. This vulnerability is leading an attacker to steal admin and all user…

  • CVE-2023-28330MedMar 23, 2023
    risk 0.35cvss 6.5epss 0.01

    Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

  • CVE-2021-36399MedMar 6, 2023
    risk 0.35cvss 5.4epss 0.01

    In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.

  • CVE-2021-36398MedMar 6, 2023
    risk 0.35cvss 5.4epss 0.01

    In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.

  • CVE-2021-36568MedSep 13, 2022
    risk 0.35cvss 5.4epss 0.01

    In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored(XSS). This affects…

  • CVE-2021-32475MedMar 11, 2022
    risk 0.35cvss 5.4epss 0.01

    ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.

  • CVE-2021-32473MedMar 11, 2022
    risk 0.35cvss 5.3epss 0.01

    It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected

  • CVE-2021-43560MedNov 22, 2021
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

  • CVE-2021-32244MedJun 16, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.

  • CVE-2021-20185MedJan 28, 2021
    risk 0.35cvss 5.3epss 0.01

    It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.

  • CVE-2021-20186MedJan 28, 2021
    risk 0.35cvss 5.4epss 0.01

    It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.

  • CVE-2020-25703MedNov 19, 2020
    risk 0.35cvss 5.3epss 0.02

    The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.

  • CVE-2020-25700MedNov 19, 2020
    risk 0.35cvss 6.5epss 0.01

    In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

  • CVE-2019-14883MedMar 18, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their…

  • CVE-2019-18210MedFeb 11, 2020
    risk 0.35cvss 5.4epss 0.01

    Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor…

  • CVE-2012-1169MedNov 14, 2019
    risk 0.35cvss 5.3epss 0.02

    Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.

  • CVE-2018-1135MedMay 25, 2018
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by changing the download URL.

  • CVE-2018-1134MedMay 25, 2018
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by changing the download URL.

Page 3 of 13