Vendor CVEs
Moodle
All CVEs
647 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-48897 | Med | 0.28 | 4.3 | 0.00 | Nov 18, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify. | ||
| CVE-2024-48896 | Med | 0.28 | 4.3 | 0.00 | Nov 18, 2024 | A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site. | ||
| CVE-2024-43439 | Med | 0.28 | 5.4 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk. | ||
| CVE-2024-38277 | Med | 0.28 | 5.4 | 0.00 | Jun 18, 2024 | A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two. | ||
| CVE-2024-38273 | Med | 0.28 | 5.4 | 0.00 | Jun 18, 2024 | Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access. | ||
| CVE-2024-33998 | Med | 0.28 | 5.4 | 0.00 | May 31, 2024 | Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features. | ||
| CVE-2022-40316 | Med | 0.28 | 4.3 | 0.01 | Sep 30, 2022 | The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. | ||
| CVE-2021-40695 | Med | 0.28 | 4.3 | 0.01 | Sep 29, 2022 | It was possible for a student to view their quiz grade before it had been released, using a quiz web service. | ||
| CVE-2021-40692 | Med | 0.28 | 4.3 | 0.01 | Sep 29, 2022 | Insufficient capability checks made it possible for teachers to download users outside of their courses. | ||
| CVE-2021-40691 | Med | 0.28 | 4.3 | 0.01 | Sep 29, 2022 | A session hijack risk was identified in the Shibboleth authentication plugin. | ||
| CVE-2020-1754 | Med | 0.28 | 4.3 | 0.01 | Aug 5, 2022 | In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups. | ||
| CVE-2020-1691 | Med | 0.28 | 5.4 | 0.01 | Aug 5, 2022 | In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting. | ||
| CVE-2022-30597 | Med | 0.28 | 5.3 | 0.01 | May 18, 2022 | A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field. | ||
| CVE-2022-30596 | Med | 0.28 | 5.4 | 0.01 | May 18, 2022 | A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk. | ||
| CVE-2021-32477 | Med | 0.28 | 4.3 | 0.01 | Mar 11, 2022 | The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected. | ||
| CVE-2021-32472 | Med | 0.28 | 4.3 | 0.01 | Mar 11, 2022 | Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected. | ||
| CVE-2019-14829 | Med | 0.28 | 4.3 | 0.01 | Mar 19, 2021 | A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode. | ||
| CVE-2019-14828 | Med | 0.28 | 4.3 | 0.01 | Mar 19, 2021 | A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be… | ||
| CVE-2021-20282 | Med | 0.28 | 5.3 | 0.01 | Mar 15, 2021 | When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. | ||
| CVE-2021-20281 | Med | 0.28 | 5.3 | 0.01 | Mar 15, 2021 | It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. | ||
| CVE-2021-20280 | Med | 0.28 | 5.4 | 0.01 | Mar 15, 2021 | Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. | ||
| CVE-2021-20279 | Med | 0.28 | 5.4 | 0.01 | Mar 15, 2021 | The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. | ||
| CVE-2021-20184 | Med | 0.28 | 4.3 | 0.01 | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades. | ||
| CVE-2021-20183 | Med | 0.28 | 5.4 | 0.01 | Jan 28, 2021 | It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries. | ||
| CVE-2020-25701 | Med | 0.28 | 5.3 | 0.01 | Nov 19, 2020 | If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to… | ||
| CVE-2019-14879 | Med | 0.28 | 5.4 | 0.01 | Jan 7, 2020 | A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable). | ||
| CVE-2012-1161 | Med | 0.28 | 4.3 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results | ||
| CVE-2012-1158 | Med | 0.28 | 4.3 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export | ||
| CVE-2019-3848 | Med | 0.28 | 4.3 | 0.01 | Mar 26, 2019 | A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was… | ||
| CVE-2019-3808 | Med | 0.28 | 5.4 | 0.01 | Mar 25, 2019 | A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is… | ||
| CVE-2017-15110 | Med | 0.28 | 4.3 | 0.01 | Nov 20, 2017 | In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other… | ||
| CVE-2017-7491 | Med | 0.28 | 4.3 | 0.01 | May 15, 2017 | In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting. | ||
| CVE-2016-3732 | Med | 0.28 | 4.3 | 0.01 | Apr 20, 2017 | The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users. | ||
| CVE-2016-8643 | Med | 0.28 | 4.3 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services. | ||
| CVE-2016-8642 | Med | 0.28 | 5.3 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, the question engine allows access to files that should not be available. | ||
| CVE-2016-5014 | Med | 0.28 | 5.4 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course. | ||
| CVE-2016-5013 | Med | 0.28 | 5.4 | 0.01 | Jan 20, 2017 | In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam. | ||
| CVE-2016-2190 | Med | 0.28 | 5.3 | 0.02 | May 22, 2016 | Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log. | ||
| CVE-2015-5336 | Med | 0.28 | 5.4 | 0.01 | Feb 22, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering… | ||
| CVE-2015-5272 | Med | 0.28 | 4.3 | 0.01 | Feb 22, 2016 | The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants." | ||
| CVE-2015-5269 | Med | 0.28 | 5.4 | 0.01 | Feb 22, 2016 | Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description. | ||
| CVE-2015-5264 | Med | 0.28 | 5.4 | 0.01 | Feb 22, 2016 | The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role. | ||
| CVE-2015-3273 | Med | 0.28 | 4.3 | 0.01 | Feb 22, 2016 | mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group… | ||
| CVE-2025-62396 | Med | 0.27 | 5.3 | 0.00 | Oct 23, 2025 | An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured. | ||
| CVE-2024-25979 | Med | 0.27 | 5.3 | 0.01 | Feb 19, 2024 | The URL parameters accepted by forum search were not limited to the allowed parameters. | ||
| CVE-2023-5540 | Med | 0.24 | 4.7 | 0.02 | Nov 9, 2023 | A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers. | ||
| CVE-2023-5539 | Med | 0.24 | 4.7 | 0.02 | Nov 9, 2023 | A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers. | ||
| CVE-2019-10134 | Low | 0.24 | 3.7 | 0.01 | Jun 26, 2019 | A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded. | ||
| CVE-2019-3847 | Med | 0.24 | 4.8 | 0.02 | Mar 27, 2019 | A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was… | ||
| CVE-2026-58341 | mod | 0.23 | 3.5 | — | Jul 28, 2026 | moodle: CSRF risk in group messaging state toggle |
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.
- risk 0.28cvss 5.4epss 0.00
A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.
- risk 0.28cvss 5.4epss 0.00
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
- risk 0.28cvss 5.4epss 0.00
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
- risk 0.28cvss 5.4epss 0.00
Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.
- risk 0.28cvss 4.3epss 0.01
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
- risk 0.28cvss 4.3epss 0.01
It was possible for a student to view their quiz grade before it had been released, using a quiz web service.
- risk 0.28cvss 4.3epss 0.01
Insufficient capability checks made it possible for teachers to download users outside of their courses.
- risk 0.28cvss 4.3epss 0.01
A session hijack risk was identified in the Shibboleth authentication plugin.
- risk 0.28cvss 4.3epss 0.01
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
- risk 0.28cvss 5.4epss 0.01
In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.
- risk 0.28cvss 5.3epss 0.01
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
- risk 0.28cvss 5.4epss 0.01
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
- risk 0.28cvss 4.3epss 0.01
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affected.
- risk 0.28cvss 4.3epss 0.01
Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected.
- risk 0.28cvss 4.3epss 0.01
A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.
- risk 0.28cvss 4.3epss 0.01
A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with the capability to create courses were assigned as a teacher in those courses, regardless of whether they had the capability to be…
- risk 0.28cvss 5.3epss 0.01
When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
- risk 0.28cvss 5.3epss 0.01
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
- risk 0.28cvss 5.4epss 0.01
Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
- risk 0.28cvss 5.4epss 0.01
The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
- risk 0.28cvss 4.3epss 0.01
It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.
- risk 0.28cvss 5.4epss 0.01
It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.
- risk 0.28cvss 5.3epss 0.01
If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method. This could lead to unintended users gaining access to the course. Versions affected: 3.9 to…
- risk 0.28cvss 5.4epss 0.01
A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).
- risk 0.28cvss 4.3epss 0.01
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
- risk 0.28cvss 4.3epss 0.01
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
- risk 0.28cvss 4.3epss 0.01
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was…
- risk 0.28cvss 5.4epss 0.01
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is…
- risk 0.28cvss 4.3epss 0.01
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other…
- risk 0.28cvss 4.3epss 0.01
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
- risk 0.28cvss 4.3epss 0.01
The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users.
- risk 0.28cvss 4.3epss 0.01
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
- risk 0.28cvss 5.3epss 0.01
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
- risk 0.28cvss 5.4epss 0.01
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
- risk 0.28cvss 5.4epss 0.01
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
- risk 0.28cvss 5.3epss 0.02
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.
- risk 0.28cvss 5.4epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the student role and entering…
- risk 0.28cvss 4.3epss 0.01
The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."
- risk 0.28cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.
- risk 0.28cvss 5.4epss 0.01
The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.
- risk 0.28cvss 4.3epss 0.01
mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated users to bypass intended access restrictions by leveraging per-group…
- risk 0.27cvss 5.3epss 0.00
An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.
- risk 0.27cvss 5.3epss 0.01
The URL parameters accepted by forum search were not limited to the allowed parameters.
- risk 0.24cvss 4.7epss 0.02
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
- risk 0.24cvss 4.7epss 0.02
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
- risk 0.24cvss 3.7epss 0.01
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
- risk 0.24cvss 4.8epss 0.02
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was…
- risk 0.23cvss 3.5epss —
moodle: CSRF risk in group messaging state toggle
Page 5 of 13