Vendor CVEs
Moodle
All CVEs
647 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-67857 | Med | 0.21 | 4.3 | 0.00 | Feb 3, 2026 | A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information… | ||
| CVE-2025-62400 | Med | 0.21 | 4.3 | 0.00 | Oct 23, 2025 | Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information. | ||
| CVE-2025-62394 | Med | 0.21 | 4.3 | 0.00 | Oct 23, 2025 | Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information. | ||
| CVE-2025-62393 | Med | 0.21 | 4.3 | 0.00 | Oct 23, 2025 | A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details. | ||
| CVE-2025-3647 | Med | 0.21 | 4.3 | 0.00 | Apr 25, 2025 | A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve. | ||
| CVE-2025-3645 | Med | 0.21 | 4.3 | 0.00 | Apr 25, 2025 | A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses. | ||
| CVE-2025-3640 | Med | 0.21 | 4.3 | 0.00 | Apr 25, 2025 | A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access. | ||
| CVE-2025-3636 | Med | 0.21 | 4.3 | 0.00 | Apr 25, 2025 | A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks. | ||
| CVE-2025-3628 | Med | 0.21 | 4.3 | 0.00 | Apr 25, 2025 | A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities. | ||
| CVE-2025-3634 | Med | 0.21 | 4.3 | 0.00 | Apr 25, 2025 | A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes. | ||
| CVE-2024-48899 | Med | 0.21 | 4.3 | 0.00 | Nov 20, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to. | ||
| CVE-2024-34006 | Med | 0.21 | 4.3 | 0.00 | May 31, 2024 | The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered. | ||
| CVE-2024-34000 | Med | 0.21 | 4.3 | 0.00 | May 31, 2024 | ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk. | ||
| CVE-2024-25982 | Med | 0.21 | 4.3 | 0.01 | Feb 19, 2024 | The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. | ||
| CVE-2024-25981 | Med | 0.21 | 4.3 | 0.01 | Feb 19, 2024 | Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers. | ||
| CVE-2024-25980 | Med | 0.21 | 4.3 | 0.01 | Feb 19, 2024 | Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers. | ||
| CVE-2023-5546 | Med | 0.21 | 4.3 | 0.01 | Nov 9, 2023 | ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. | ||
| CVE-2022-40208 | Med | 0.21 | 4.3 | 0.01 | Mar 24, 2023 | In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt. | ||
| CVE-2023-28336 | Med | 0.21 | 4.3 | 0.01 | Mar 23, 2023 | Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access. | ||
| CVE-2023-28334 | Med | 0.21 | 4.3 | 0.01 | Mar 23, 2023 | Authenticated users were able to enumerate other users' names via the learning plans page. | ||
| CVE-2023-1402 | Med | 0.21 | 4.3 | 0.01 | Mar 23, 2023 | The course participation report required additional checks to prevent roles being displayed which the user did not have access to view. | ||
| CVE-2020-36633 | Med | 0.21 | 4.3 | 0.00 | Dec 27, 2022 | A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to… | ||
| CVE-2022-30598 | Med | 0.21 | 4.3 | 0.01 | May 18, 2022 | A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it. | ||
| CVE-2022-0984 | Med | 0.21 | 4.3 | 0.01 | Apr 29, 2022 | Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges. | ||
| CVE-2022-0985 | Med | 0.21 | 4.3 | 0.01 | Apr 29, 2022 | Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability. | ||
| CVE-2022-0334 | Med | 0.21 | 4.3 | 0.01 | Jan 25, 2022 | A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view… | ||
| CVE-2021-20283 | Med | 0.21 | 4.3 | 0.01 | Mar 15, 2021 | The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. | ||
| CVE-2012-1159 | Med | 0.21 | 4.3 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2: Overview report allows users to see hidden courses | ||
| CVE-2012-1157 | Med | 0.21 | 4.3 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default | ||
| CVE-2019-10189 | Med | 0.21 | 4.3 | 0.01 | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment. | ||
| CVE-2019-10188 | Med | 0.21 | 4.3 | 0.01 | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz. | ||
| CVE-2019-10187 | Med | 0.21 | 4.3 | 0.01 | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to. | ||
| CVE-2019-3852 | Med | 0.21 | 4.3 | 0.01 | Mar 26, 2019 | A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities | ||
| CVE-2019-3851 | Med | 0.21 | 4.3 | 0.01 | Mar 26, 2019 | A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page. | ||
| CVE-2019-3850 | Med | 0.21 | 4.3 | 0.01 | Mar 26, 2019 | A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header… | ||
| CVE-2018-10890 | Med | 0.21 | 4.3 | 0.02 | Jul 10, 2018 | A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories. | ||
| CVE-2018-10889 | Med | 0.21 | 4.3 | 0.02 | Jul 10, 2018 | A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester. | ||
| CVE-2018-1136 | Med | 0.21 | 4.3 | 0.01 | May 25, 2018 | An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move… | ||
| CVE-2018-1044 | Med | 0.21 | 4.3 | 0.01 | Jan 22, 2018 | In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings. | ||
| CVE-2017-12157 | Med | 0.21 | 4.3 | 0.01 | Sep 18, 2017 | In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access. | ||
| CVE-2017-7531 | Med | 0.21 | 4.3 | 0.01 | Jul 17, 2017 | In Moodle 3.3, the course overview block reveals activities in hidden courses. | ||
| CVE-2016-3733 | Med | 0.21 | 4.3 | 0.01 | Apr 20, 2017 | The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber. | ||
| CVE-2016-2159 | Med | 0.21 | 4.3 | 0.01 | May 22, 2016 | The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated users to bypass intended due-date restrictions by leveraging the student role for… | ||
| CVE-2016-2158 | Med | 0.21 | 4.3 | 0.02 | May 22, 2016 | lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by… | ||
| CVE-2016-2156 | Med | 0.21 | 4.3 | 0.02 | May 22, 2016 | calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive… | ||
| CVE-2016-2155 | Med | 0.21 | 4.3 | 0.02 | May 22, 2016 | The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging… | ||
| CVE-2016-2154 | Med | 0.21 | 4.3 | 0.02 | May 22, 2016 | admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a… | ||
| CVE-2016-2151 | Med | 0.21 | 4.3 | 0.02 | May 22, 2016 | user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover… | ||
| CVE-2016-0724 | Med | 0.21 | 4.3 | 0.02 | Feb 22, 2016 | The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which… | ||
| CVE-2015-5342 | Med | 0.21 | 4.3 | 0.01 | Feb 22, 2016 | The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state. |
- risk 0.21cvss 4.3epss 0.00
A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information…
- risk 0.21cvss 4.3epss 0.00
Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.
- risk 0.21cvss 4.3epss 0.00
Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.
- risk 0.21cvss 4.3epss 0.00
A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.
- risk 0.21cvss 4.3epss 0.00
A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.
- risk 0.21cvss 4.3epss 0.00
A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.
- risk 0.21cvss 4.3epss 0.00
A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.
- risk 0.21cvss 4.3epss 0.00
A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.
- risk 0.21cvss 4.3epss 0.00
A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.
- risk 0.21cvss 4.3epss 0.00
A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.
- risk 0.21cvss 4.3epss 0.00
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
- risk 0.21cvss 4.3epss 0.00
The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.
- risk 0.21cvss 4.3epss 0.00
ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.
- risk 0.21cvss 4.3epss 0.01
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
- risk 0.21cvss 4.3epss 0.01
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
- risk 0.21cvss 4.3epss 0.01
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
- risk 0.21cvss 4.3epss 0.01
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
- risk 0.21cvss 4.3epss 0.01
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.
- risk 0.21cvss 4.3epss 0.01
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
- risk 0.21cvss 4.3epss 0.01
Authenticated users were able to enumerate other users' names via the learning plans page.
- risk 0.21cvss 4.3epss 0.01
The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.
- risk 0.21cvss 4.3epss 0.00
A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to…
- risk 0.21cvss 4.3epss 0.01
A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.
- risk 0.21cvss 4.3epss 0.01
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
- risk 0.21cvss 4.3epss 0.01
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.
- risk 0.21cvss 4.3epss 0.01
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view…
- risk 0.21cvss 4.3epss 0.01
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
- risk 0.21cvss 4.3epss 0.01
Moodle before 2.2.2: Overview report allows users to see hidden courses
- risk 0.21cvss 4.3epss 0.01
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
- risk 0.21cvss 4.3epss 0.01
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.
- risk 0.21cvss 4.3epss 0.01
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
- risk 0.21cvss 4.3epss 0.01
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.
- risk 0.21cvss 4.3epss 0.01
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities
- risk 0.21cvss 4.3epss 0.01
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
- risk 0.21cvss 4.3epss 0.01
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header…
- risk 0.21cvss 4.3epss 0.02
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.
- risk 0.21cvss 4.3epss 0.02
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.
- risk 0.21cvss 4.3epss 0.01
An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move…
- risk 0.21cvss 4.3epss 0.01
In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.
- risk 0.21cvss 4.3epss 0.01
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
- risk 0.21cvss 4.3epss 0.01
In Moodle 3.3, the course overview block reveals activities in hidden courses.
- risk 0.21cvss 4.3epss 0.01
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.
- risk 0.21cvss 4.3epss 0.01
The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated users to bypass intended due-date restrictions by leveraging the student role for…
- risk 0.21cvss 4.3epss 0.02
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by…
- risk 0.21cvss 4.3epss 0.02
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive…
- risk 0.21cvss 4.3epss 0.02
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging…
- risk 0.21cvss 4.3epss 0.02
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a…
- risk 0.21cvss 4.3epss 0.02
user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover…
- risk 0.21cvss 4.3epss 0.02
The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which…
- risk 0.21cvss 4.3epss 0.01
The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.
Page 6 of 13