VYPR

Vendor CVEs

Moodle

All CVEs

647 total · sorted by risk
  • CVE-2025-67857MedFeb 3, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information…

  • CVE-2025-62400MedOct 23, 2025
    risk 0.21cvss 4.3epss 0.00

    Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.

  • CVE-2025-62394MedOct 23, 2025
    risk 0.21cvss 4.3epss 0.00

    Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.

  • CVE-2025-62393MedOct 23, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details.

  • CVE-2025-3647MedApr 25, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.

  • CVE-2025-3645MedApr 25, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.

  • CVE-2025-3640MedApr 25, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.

  • CVE-2025-3636MedApr 25, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.

  • CVE-2025-3628MedApr 25, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.

  • CVE-2025-3634MedApr 25, 2025
    risk 0.21cvss 4.3epss 0.00

    A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.

  • CVE-2024-48899MedNov 20, 2024
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.

  • CVE-2024-34006MedMay 31, 2024
    risk 0.21cvss 4.3epss 0.00

    The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.

  • CVE-2024-34000MedMay 31, 2024
    risk 0.21cvss 4.3epss 0.00

    ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.

  • CVE-2024-25982MedFeb 19, 2024
    risk 0.21cvss 4.3epss 0.01

    The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

  • CVE-2024-25981MedFeb 19, 2024
    risk 0.21cvss 4.3epss 0.01

    Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

  • CVE-2024-25980MedFeb 19, 2024
    risk 0.21cvss 4.3epss 0.01

    Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

  • CVE-2023-5546MedNov 9, 2023
    risk 0.21cvss 4.3epss 0.01

    ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

  • CVE-2022-40208MedMar 24, 2023
    risk 0.21cvss 4.3epss 0.01

    In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.

  • CVE-2023-28336MedMar 23, 2023
    risk 0.21cvss 4.3epss 0.01

    Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

  • CVE-2023-28334MedMar 23, 2023
    risk 0.21cvss 4.3epss 0.01

    Authenticated users were able to enumerate other users' names via the learning plans page.

  • CVE-2023-1402MedMar 23, 2023
    risk 0.21cvss 4.3epss 0.01

    The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.

  • CVE-2020-36633MedDec 27, 2022
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to…

  • CVE-2022-30598MedMay 18, 2022
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.

  • CVE-2022-0984MedApr 29, 2022
    risk 0.21cvss 4.3epss 0.01

    Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

  • CVE-2022-0985MedApr 29, 2022
    risk 0.21cvss 4.3epss 0.01

    Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.

  • CVE-2022-0334MedJan 25, 2022
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view…

  • CVE-2021-20283MedMar 15, 2021
    risk 0.21cvss 4.3epss 0.01

    The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2012-1159MedNov 14, 2019
    risk 0.21cvss 4.3epss 0.01

    Moodle before 2.2.2: Overview report allows users to see hidden courses

  • CVE-2012-1157MedNov 14, 2019
    risk 0.21cvss 4.3epss 0.01

    Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default

  • CVE-2019-10189MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.

  • CVE-2019-10188MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.

  • CVE-2019-10187MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.

  • CVE-2019-3852MedMar 26, 2019
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities

  • CVE-2019-3851MedMar 26, 2019
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.

  • CVE-2019-3850MedMar 26, 2019
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header…

  • CVE-2018-10890MedJul 10, 2018
    risk 0.21cvss 4.3epss 0.02

    A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetching course categories.

  • CVE-2018-10889MedJul 10, 2018
    risk 0.21cvss 4.3epss 0.02

    A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.

  • CVE-2018-1136MedMay 25, 2018
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is normally not a security issue because a personal dashboard is visible to this user only. Through this security vulnerability, users can move…

  • CVE-2018-1044MedJan 22, 2018
    risk 0.21cvss 4.3epss 0.01

    In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.

  • CVE-2017-12157MedSep 18, 2017
    risk 0.21cvss 4.3epss 0.01

    In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

  • CVE-2017-7531MedJul 17, 2017
    risk 0.21cvss 4.3epss 0.01

    In Moodle 3.3, the course overview block reveals activities in hidden courses.

  • CVE-2016-3733MedApr 20, 2017
    risk 0.21cvss 4.3epss 0.01

    The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.

  • CVE-2016-2159MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.01

    The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows remote authenticated users to bypass intended due-date restrictions by leveraging the student role for…

  • CVE-2016-2158MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.02

    lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from the navigation branch by…

  • CVE-2016-2156MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.02

    calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive…

  • CVE-2016-2155MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.02

    The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings by leveraging…

  • CVE-2016-2154MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.02

    admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to a…

  • CVE-2016-2151MedMay 22, 2016
    risk 0.21cvss 4.3epss 0.02

    user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhiddenuserfields capability, which allows remote authenticated users to discover…

  • CVE-2016-0724MedFeb 22, 2016
    risk 0.21cvss 4.3epss 0.02

    The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which…

  • CVE-2015-5342MedFeb 22, 2016
    risk 0.21cvss 4.3epss 0.01

    The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.

Page 6 of 13