VYPR

Vendor CVEs

Moodle

All CVEs

647 total · sorted by risk
  • CVE-2024-48897MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.

  • CVE-2024-48896MedNov 18, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.

  • CVE-2024-43439MedNov 11, 2024
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.

  • CVE-2024-38277MedJun 18, 2024
    risk 0.28cvss 5.4epss 0.00

    A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

  • CVE-2024-38273MedJun 18, 2024
    risk 0.28cvss 5.4epss 0.00

    Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

  • CVE-2024-33998MedMay 31, 2024
    risk 0.28cvss 5.4epss 0.00

    Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

  • CVE-2022-40316MedSep 30, 2022
    risk 0.28cvss 4.3epss 0.01

    The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

  • CVE-2021-40695MedSep 29, 2022
    risk 0.28cvss 4.3epss 0.01

    It was possible for a student to view their quiz grade before it had been released, using a quiz web service.

  • CVE-2021-40692MedSep 29, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient capability checks made it possible for teachers to download users outside of their courses.

  • CVE-2021-40691MedSep 29, 2022
    risk 0.28cvss 4.3epss 0.01

    A session hijack risk was identified in the Shibboleth authentication plugin.

  • CVE-2020-1754MedAug 5, 2022
    risk 0.28cvss 4.3epss 0.01

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

  • CVE-2020-1691MedAug 5, 2022
    risk 0.28cvss 5.4epss 0.01

    In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

  • CVE-2022-30597MedMay 18, 2022
    risk 0.28cvss 5.3epss 0.01

    A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.

  • CVE-2022-30596MedMay 18, 2022
    risk 0.28cvss 5.4epss 0.01

    A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

  • CVE-2021-32477MedMar 11, 2022
    risk 0.28cvss 4.3epss 0.01

    The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.

  • CVE-2021-32472MedMar 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected.

  • CVE-2019-14829MedMar 19, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.

  • CVE-2019-14828MedMar 19, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be…

  • CVE-2021-20282MedMar 15, 2021
    risk 0.28cvss 5.3epss 0.01

    When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-20281MedMar 15, 2021
    risk 0.28cvss 5.3epss 0.01

    It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-20280MedMar 15, 2021
    risk 0.28cvss 5.4epss 0.01

    Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-20279MedMar 15, 2021
    risk 0.28cvss 5.4epss 0.01

    The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2021-20184MedJan 28, 2021
    risk 0.28cvss 4.3epss 0.01

    It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.

  • CVE-2021-20183MedJan 28, 2021
    risk 0.28cvss 5.4epss 0.01

    It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

  • CVE-2020-25701MedNov 19, 2020
    risk 0.28cvss 5.3epss 0.01

    If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to…

  • CVE-2019-14879MedJan 7, 2020
    risk 0.28cvss 5.4epss 0.01

    A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).

  • CVE-2012-1161MedNov 14, 2019
    risk 0.28cvss 4.3epss 0.01

    Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results

  • CVE-2012-1158MedNov 14, 2019
    risk 0.28cvss 4.3epss 0.01

    Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export

  • CVE-2019-3848MedMar 26, 2019
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was…

  • CVE-2019-3808MedMar 25, 2019
    risk 0.28cvss 5.4epss 0.01

    A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is…

  • CVE-2017-15110MedNov 20, 2017
    risk 0.28cvss 4.3epss 0.01

    In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other…

  • CVE-2017-7491MedMay 15, 2017
    risk 0.28cvss 4.3epss 0.01

    In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.

  • CVE-2016-3732MedApr 20, 2017
    risk 0.28cvss 4.3epss 0.01

    The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users.

  • CVE-2016-8643MedJan 20, 2017
    risk 0.28cvss 4.3epss 0.01

    In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.

  • CVE-2016-8642MedJan 20, 2017
    risk 0.28cvss 5.3epss 0.01

    In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.

  • CVE-2016-5014MedJan 20, 2017
    risk 0.28cvss 5.4epss 0.01

    In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.

  • CVE-2016-5013MedJan 20, 2017
    risk 0.28cvss 5.4epss 0.01

    In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.

  • CVE-2016-2190MedMay 22, 2016
    risk 0.28cvss 5.3epss 0.02

    Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.

  • CVE-2015-5336MedFeb 22, 2016
    risk 0.28cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering…

  • CVE-2015-5272MedFeb 22, 2016
    risk 0.28cvss 4.3epss 0.01

    The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."

  • CVE-2015-5269MedFeb 22, 2016
    risk 0.28cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.

  • CVE-2015-5264MedFeb 22, 2016
    risk 0.28cvss 5.4epss 0.01

    The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.

  • CVE-2015-3273MedFeb 22, 2016
    risk 0.28cvss 4.3epss 0.01

    mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group…

  • CVE-2025-62396MedOct 23, 2025
    risk 0.27cvss 5.3epss 0.00

    An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

  • CVE-2024-25979MedFeb 19, 2024
    risk 0.27cvss 5.3epss 0.01

    The URL parameters accepted by forum search were not limited to the allowed parameters.

  • CVE-2023-5540MedNov 9, 2023
    risk 0.24cvss 4.7epss 0.02

    A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.

  • CVE-2023-5539MedNov 9, 2023
    risk 0.24cvss 4.7epss 0.02

    A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.

  • CVE-2019-10134LowJun 26, 2019
    risk 0.24cvss 3.7epss 0.01

    A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.

  • CVE-2019-3847MedMar 27, 2019
    risk 0.24cvss 4.8epss 0.02

    A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was…

  • CVE-2026-58341modJul 28, 2026
    risk 0.23cvss 3.5epss —

    moodle: CSRF risk in group messaging state toggle

Page 5 of 13