Vendor CVEs
Moodle
All CVEs
647 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-1081 | Med | 0.35 | 5.3 | 0.01 | Apr 4, 2018 | A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after… | ||
| CVE-2018-1045 | Med | 0.35 | 5.4 | 0.01 | Jan 22, 2018 | In Moodle 3.x, there is XSS via a calendar event name. | ||
| CVE-2017-7532 | Med | 0.35 | 6.5 | 0.01 | Jul 17, 2017 | In Moodle 3.x, course creators are able to change system default settings for courses. | ||
| CVE-2017-7490 | Med | 0.35 | 5.3 | 0.01 | May 15, 2017 | In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing. | ||
| CVE-2016-3731 | Med | 0.35 | 5.3 | 0.02 | Apr 20, 2017 | Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions. | ||
| CVE-2017-7298 | Med | 0.35 | 5.4 | 0.01 | Mar 29, 2017 | In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element. | ||
| CVE-2017-2643 | Med | 0.35 | 5.3 | 0.02 | Mar 26, 2017 | In Moodle 3.2.x, global search displays user names for unauthenticated users. | ||
| CVE-2017-2576 | Med | 0.35 | 5.3 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums. | ||
| CVE-2016-8644 | Med | 0.35 | 5.3 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context. | ||
| CVE-2016-5012 | Med | 0.35 | 5.3 | 0.01 | Jan 20, 2017 | In Moodle 3.x, glossary search displays entries without checking user permissions to view them. | ||
| CVE-2025-62397 | Med | 0.34 | 5.3 | 0.00 | Oct 23, 2025 | The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance. | ||
| CVE-2021-36403 | Med | 0.34 | 5.3 | 0.01 | Mar 6, 2023 | In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk. | ||
| CVE-2021-36402 | Med | 0.34 | 5.3 | 0.01 | Mar 6, 2023 | In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk. | ||
| CVE-2021-36400 | Med | 0.34 | 5.3 | 0.01 | Mar 6, 2023 | In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. | ||
| CVE-2021-36397 | Med | 0.34 | 5.3 | 0.01 | Mar 6, 2023 | In Moodle, insufficient capability checks meant message deletions were not limited to the current user. | ||
| CVE-2020-1755 | Med | 0.34 | 5.3 | 0.01 | Aug 16, 2022 | In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks. | ||
| CVE-2022-50943 | Med | 0.33 | 6.1 | 0.00 | May 10, 2026 | Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary… | ||
| CVE-2025-67851 | Med | 0.33 | 6.1 | 0.00 | Feb 3, 2026 | A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute.… | ||
| CVE-2024-33997 | Med | 0.33 | 6.1 | 0.00 | May 31, 2024 | Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation. | ||
| CVE-2023-28332 | Med | 0.33 | 6.1 | 0.01 | Mar 23, 2023 | If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk. | ||
| CVE-2023-28331 | Med | 0.33 | 6.1 | 0.01 | Mar 23, 2023 | Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk. | ||
| CVE-2020-14320 | Med | 0.33 | 6.1 | 0.01 | Aug 16, 2022 | In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk. | ||
| CVE-2022-35652 | Med | 0.33 | 6.1 | 0.01 | Jul 25, 2022 | An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful… | ||
| CVE-2021-32478 | Med | 0.33 | 6.1 | 0.01 | Mar 11, 2022 | The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected. | ||
| CVE-2020-25628 | Med | 0.33 | 6.1 | 0.01 | Dec 8, 2020 | The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14. | ||
| CVE-2020-25702 | Med | 0.33 | 6.1 | 0.01 | Nov 19, 2020 | In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10. | ||
| CVE-2019-14881 | Med | 0.33 | 6.1 | 0.01 | Mar 18, 2020 | A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed. | ||
| CVE-2017-12156 | Med | 0.33 | 6.1 | 0.01 | Sep 18, 2017 | Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback. | ||
| CVE-2017-2644 | Med | 0.33 | 6.1 | 0.01 | Mar 26, 2017 | In Moodle 3.x, XSS can occur via evidence of prior learning. | ||
| CVE-2016-2153 | Med | 0.33 | 6.1 | 0.01 | May 22, 2016 | Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field… | ||
| CVE-2016-2152 | Med | 0.33 | 6.1 | 0.01 | May 22, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field. | ||
| CVE-2015-5337 | Med | 0.33 | 6.1 | 0.01 | Feb 22, 2016 | Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file. | ||
| CVE-2015-3275 | Med | 0.33 | 6.1 | 0.01 | Feb 22, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1)… | ||
| CVE-2015-3274 | Med | 0.33 | 6.1 | 0.01 | Feb 22, 2016 | Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an… | ||
| CVE-2021-40694 | Med | 0.32 | 4.9 | 0.01 | Sep 29, 2022 | Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account. | ||
| CVE-2021-36401 | Med | 0.31 | 4.8 | 0.01 | Mar 6, 2023 | In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk. | ||
| CVE-2023-30944 | Med | 0.29 | 5.6 | 0.01 | May 2, 2023 | The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the… | ||
| CVE-2025-67856 | Med | 0.28 | 5.4 | 0.00 | Feb 3, 2026 | A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to,… | ||
| CVE-2025-67855 | Med | 0.28 | 5.4 | 0.00 | Feb 3, 2026 | A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This vulnerability arises from insufficient sanitization of URL parameters, allowing attackers to inject malicious scripts through… | ||
| CVE-2025-62401 | Med | 0.28 | 5.4 | 0.00 | Oct 23, 2025 | An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment. | ||
| CVE-2025-62398 | Med | 0.28 | 5.4 | 0.00 | Oct 23, 2025 | A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts. | ||
| CVE-2025-62395 | Med | 0.28 | 4.3 | 0.00 | Oct 23, 2025 | A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data. | ||
| CVE-2025-60511 | Med | 0.28 | 4.3 | 0.00 | Oct 21, 2025 | Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in /blocks/openai_chat/api/completion.php. An authenticated student can impersonate another user's… | ||
| CVE-2025-4513 | Med | 0.28 | 4.3 | 0.00 | May 10, 2025 | A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of the file /auth/userkey/logout.php of the component Logout. The manipulation of the argument return… | ||
| CVE-2025-3644 | Med | 0.28 | 4.3 | 0.00 | Apr 25, 2025 | A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify. | ||
| CVE-2025-3643 | Med | 0.28 | 5.4 | 0.00 | Apr 25, 2025 | A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk. | ||
| CVE-2025-3627 | Med | 0.28 | 4.3 | 0.00 | Apr 25, 2025 | A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA). | ||
| CVE-2024-45691 | Med | 0.28 | 5.4 | 0.00 | Nov 20, 2024 | A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values. | ||
| CVE-2024-48901 | Med | 0.28 | 4.3 | 0.00 | Nov 18, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report. | ||
| CVE-2024-48898 | Med | 0.28 | 4.3 | 0.00 | Nov 18, 2024 | A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from. |
- risk 0.35cvss 5.3epss 0.01
A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after…
- risk 0.35cvss 5.4epss 0.01
In Moodle 3.x, there is XSS via a calendar event name.
- risk 0.35cvss 6.5epss 0.01
In Moodle 3.x, course creators are able to change system default settings for courses.
- risk 0.35cvss 5.3epss 0.01
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
- risk 0.35cvss 5.3epss 0.02
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.
- risk 0.35cvss 5.4epss 0.01
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.
- risk 0.35cvss 5.3epss 0.02
In Moodle 3.2.x, global search displays user names for unauthenticated users.
- risk 0.35cvss 5.3epss 0.01
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
- risk 0.35cvss 5.3epss 0.01
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
- risk 0.35cvss 5.3epss 0.01
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
- risk 0.34cvss 5.3epss 0.00
The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.
- risk 0.34cvss 5.3epss 0.01
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
- risk 0.34cvss 5.3epss 0.01
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.
- risk 0.34cvss 5.3epss 0.01
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
- risk 0.34cvss 5.3epss 0.01
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
- risk 0.34cvss 5.3epss 0.01
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
- risk 0.33cvss 6.1epss 0.00
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary…
- risk 0.33cvss 6.1epss 0.00
A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute.…
- risk 0.33cvss 6.1epss 0.00
Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.
- risk 0.33cvss 6.1epss 0.01
If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.
- risk 0.33cvss 6.1epss 0.01
Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
- risk 0.33cvss 6.1epss 0.01
In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.
- risk 0.33cvss 6.1epss 0.01
An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful…
- risk 0.33cvss 6.1epss 0.01
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.
- risk 0.33cvss 6.1epss 0.01
The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.
- risk 0.33cvss 6.1epss 0.01
In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.
- risk 0.33cvss 6.1epss 0.01
A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.
- risk 0.33cvss 6.1epss 0.01
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
- risk 0.33cvss 6.1epss 0.01
In Moodle 3.x, XSS can occur via evidence of prior learning.
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field…
- risk 0.33cvss 6.1epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field.
- risk 0.33cvss 6.1epss 0.01
Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.
- risk 0.33cvss 6.1epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1)…
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an…
- risk 0.32cvss 4.9epss 0.01
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.
- risk 0.31cvss 4.8epss 0.01
In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.
- risk 0.29cvss 5.6epss 0.01
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the…
- risk 0.28cvss 5.4epss 0.00
A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to,…
- risk 0.28cvss 5.4epss 0.00
A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This vulnerability arises from insufficient sanitization of URL parameters, allowing attackers to inject malicious scripts through…
- risk 0.28cvss 5.4epss 0.00
An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.
- risk 0.28cvss 5.4epss 0.00
A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.
- risk 0.28cvss 4.3epss 0.00
A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.
- risk 0.28cvss 4.3epss 0.00
Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in /blocks/openai_chat/api/completion.php. An authenticated student can impersonate another user's…
- risk 0.28cvss 4.3epss 0.00
A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of the file /auth/userkey/logout.php of the component Logout. The manipulation of the argument return…
- risk 0.28cvss 4.3epss 0.00
A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.
- risk 0.28cvss 5.4epss 0.00
A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.
- risk 0.28cvss 4.3epss 0.00
A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).
- risk 0.28cvss 5.4epss 0.00
A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.
Page 4 of 13