VYPR

Vendor CVEs

Moodle

All CVEs

647 total · sorted by risk
  • CVE-2018-1081MedApr 4, 2018
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after…

  • CVE-2018-1045MedJan 22, 2018
    risk 0.35cvss 5.4epss 0.01

    In Moodle 3.x, there is XSS via a calendar event name.

  • CVE-2017-7532MedJul 17, 2017
    risk 0.35cvss 6.5epss 0.01

    In Moodle 3.x, course creators are able to change system default settings for courses.

  • CVE-2017-7490MedMay 15, 2017
    risk 0.35cvss 5.3epss 0.01

    In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.

  • CVE-2016-3731MedApr 20, 2017
    risk 0.35cvss 5.3epss 0.02

    Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.

  • CVE-2017-7298MedMar 29, 2017
    risk 0.35cvss 5.4epss 0.01

    In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.

  • CVE-2017-2643MedMar 26, 2017
    risk 0.35cvss 5.3epss 0.02

    In Moodle 3.2.x, global search displays user names for unauthenticated users.

  • CVE-2017-2576MedJan 20, 2017
    risk 0.35cvss 5.3epss 0.01

    In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.

  • CVE-2016-8644MedJan 20, 2017
    risk 0.35cvss 5.3epss 0.01

    In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.

  • CVE-2016-5012MedJan 20, 2017
    risk 0.35cvss 5.3epss 0.01

    In Moodle 3.x, glossary search displays entries without checking user permissions to view them.

  • CVE-2025-62397MedOct 23, 2025
    risk 0.34cvss 5.3epss 0.00

    The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

  • CVE-2021-36403MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.

  • CVE-2021-36402MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.

  • CVE-2021-36400MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.

  • CVE-2021-36397MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, insufficient capability checks meant message deletions were not limited to the current user.

  • CVE-2020-1755MedAug 16, 2022
    risk 0.34cvss 5.3epss 0.01

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

  • CVE-2022-50943MedMay 10, 2026
    risk 0.33cvss 6.1epss 0.00

    Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary…

  • CVE-2025-67851MedFeb 3, 2026
    risk 0.33cvss 6.1epss 0.00

    A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute.…

  • CVE-2024-33997MedMay 31, 2024
    risk 0.33cvss 6.1epss 0.00

    Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

  • CVE-2023-28332MedMar 23, 2023
    risk 0.33cvss 6.1epss 0.01

    If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.

  • CVE-2023-28331MedMar 23, 2023
    risk 0.33cvss 6.1epss 0.01

    Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.

  • CVE-2020-14320MedAug 16, 2022
    risk 0.33cvss 6.1epss 0.01

    In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.

  • CVE-2022-35652MedJul 25, 2022
    risk 0.33cvss 6.1epss 0.01

    An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful…

  • CVE-2021-32478MedMar 11, 2022
    risk 0.33cvss 6.1epss 0.01

    The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.

  • CVE-2020-25628MedDec 8, 2020
    risk 0.33cvss 6.1epss 0.01

    The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 to 3.5.13 and earlier unsupported versions. Fixed in 3.9.2, 3.8.5, 3.7.8 and 3.5.14.

  • CVE-2020-25702MedNov 19, 2020
    risk 0.33cvss 6.1epss 0.01

    In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.

  • CVE-2019-14881MedMar 18, 2020
    risk 0.33cvss 6.1epss 0.01

    A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

  • CVE-2017-12156MedSep 18, 2017
    risk 0.33cvss 6.1epss 0.01

    Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

  • CVE-2017-2644MedMar 26, 2017
    risk 0.33cvss 6.1epss 0.01

    In Moodle 3.x, XSS can occur via evidence of prior learning.

  • CVE-2016-2153MedMay 22, 2016
    risk 0.33cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted field…

  • CVE-2016-2152MedMay 22, 2016
    risk 0.33cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an external DB profile field.

  • CVE-2015-5337MedFeb 22, 2016
    risk 0.33cvss 6.1epss 0.01

    Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted .swf file.

  • CVE-2015-3275MedFeb 22, 2016
    risk 0.33cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1)…

  • CVE-2015-3274MedFeb 22, 2016
    risk 0.33cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to inject arbitrary web script or HTML by leveraging absence of an…

  • CVE-2021-40694MedSep 29, 2022
    risk 0.32cvss 4.9epss 0.01

    Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.

  • CVE-2021-36401MedMar 6, 2023
    risk 0.31cvss 4.8epss 0.01

    In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.

  • CVE-2023-30944MedMay 2, 2023
    risk 0.29cvss 5.6epss 0.01

    The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the…

  • CVE-2025-67856MedFeb 3, 2026
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to,…

  • CVE-2025-67855MedFeb 3, 2026
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This vulnerability arises from insufficient sanitization of URL parameters, allowing attackers to inject malicious scripts through…

  • CVE-2025-62401MedOct 23, 2025
    risk 0.28cvss 5.4epss 0.00

    An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.

  • CVE-2025-62398MedOct 23, 2025
    risk 0.28cvss 5.4epss 0.00

    A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

  • CVE-2025-62395MedOct 23, 2025
    risk 0.28cvss 4.3epss 0.00

    A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

  • CVE-2025-60511MedOct 21, 2025
    risk 0.28cvss 4.3epss 0.00

    Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in /blocks/openai_chat/api/completion.php. An authenticated student can impersonate another user's…

  • CVE-2025-4513MedMay 10, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of the file /auth/userkey/logout.php of the component Logout. The manipulation of the argument return…

  • CVE-2025-3644MedApr 25, 2025
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.

  • CVE-2025-3643MedApr 25, 2025
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

  • CVE-2025-3627MedApr 25, 2025
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).

  • CVE-2024-45691MedNov 20, 2024
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.

  • CVE-2024-48901MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.

  • CVE-2024-48898MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.

Page 4 of 13