Vendor CVEs
Moodle
All CVEs
646 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0333 | Low | 0.18 | 3.8 | 0.01 | Jan 25, 2022 | A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events. | ||
| CVE-2012-1160 | Low | 0.18 | 2.7 | 0.01 | Nov 14, 2019 | Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php | ||
| CVE-2025-67852 | Low | 0.16 | 3.5 | 0.00 | Feb 3, 2026 | A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could… | ||
| CVE-2025-3635 | Low | 0.16 | 3.5 | 0.00 | Apr 25, 2025 | A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks. | ||
| CVE-2024-25983 | Low | 0.16 | 3.5 | 0.01 | Feb 19, 2024 | Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page). | ||
| CVE-2023-5551 | Low | 0.14 | 3.3 | 0.00 | Nov 9, 2023 | Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups. | ||
| CVE-2023-5549 | Low | 0.14 | 3.3 | 0.01 | Nov 9, 2023 | Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage. | ||
| CVE-2023-5548 | Low | 0.14 | 3.3 | 0.00 | Nov 9, 2023 | Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. | ||
| CVE-2023-5547 | Low | 0.14 | 3.3 | 0.01 | Nov 9, 2023 | The course upload preview contained an XSS risk for users uploading unsafe data. | ||
| CVE-2023-5545 | Low | 0.14 | 3.3 | 0.01 | Nov 9, 2023 | H5P metadata automatically populated the author with the user's username, which could be sensitive information. | ||
| CVE-2023-5542 | Low | 0.14 | 3.3 | 0.00 | Nov 9, 2023 | Students in "Only see own membership" groups could see other students in the group, which should be hidden. | ||
| CVE-2023-5541 | Low | 0.14 | 3.3 | 0.01 | Nov 9, 2023 | The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content. | ||
| CVE-2025-3637 | Low | 0.13 | 3.1 | 0.00 | Apr 25, 2025 | A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and… | ||
| CVE-2019-10133 | Low | 0.13 | 3.1 | 0.01 | Jun 26, 2019 | A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs. | ||
| CVE-2024-43425 | Hig | 0.10 | 8.1 | 0.88 | Nov 7, 2024 | A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions. | ||
| CVE-2013-3630 | 0.06 | — | 0.43 | Nov 1, 2013 | Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor. | |||
| CVE-2022-35650 | Hig | 0.04 | 7.5 | 0.49 | Jul 25, 2022 | The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to… | ||
| CVE-2019-3810 | Med | 0.04 | 6.1 | 0.14 | Mar 25, 2019 | A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by… | ||
| CVE-2006-0147 | 0.04 | — | 0.13 | Jan 9, 2006 | Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote… | |||
| CVE-2006-0146 | 0.04 | — | 0.13 | Jan 9, 2006 | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to… | |||
| CVE-2009-1171 | 0.03 | — | 0.06 | Mar 30, 2009 | The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file. | |||
| CVE-2007-6538 | 0.03 | — | 0.04 | Dec 27, 2007 | SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2007-1647 | 0.03 | — | 0.03 | Mar 24, 2007 | Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session… | |||
| CVE-2006-5219 | 0.03 | — | 0.02 | Oct 10, 2006 | SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter. | |||
| CVE-2006-3951 | 0.03 | — | 0.03 | Aug 1, 2006 | PHP remote file inclusion vulnerability in moodle.php in Mam-moodle alpha component (com_moodle) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |||
| CVE-2004-1978 | 0.03 | — | 0.02 | Apr 30, 2004 | Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter. | |||
| CVE-2022-35649 | Cri | 0.01 | 9.8 | 0.09 | Jul 25, 2022 | The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this… | ||
| CVE-2008-1502 | 0.01 | — | 0.10 | Mar 25, 2008 | The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing… | |||
| CVE-2025-32045 | Med | 0.00 | 5.3 | 0.00 | Apr 25, 2025 | A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades. | ||
| CVE-2025-26532 | Low | 0.00 | 3.1 | 0.00 | Feb 24, 2025 | Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored. | ||
| CVE-2025-26531 | Low | 0.00 | 3.1 | 0.00 | Feb 24, 2025 | Insufficient capability checks made it possible to disable badges a user does not have permission to access. | ||
| CVE-2025-26530 | Hig | 0.00 | 8.3 | 0.00 | Feb 24, 2025 | The question bank filter required additional sanitizing to prevent a reflected XSS risk. | ||
| CVE-2025-26529 | Hig | 0.00 | 8.3 | 0.01 | Feb 24, 2025 | Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk. | ||
| CVE-2025-26528 | Low | 0.00 | 3.4 | 0.00 | Feb 24, 2025 | The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk. | ||
| CVE-2025-26527 | Med | 0.00 | 5.3 | 0.00 | Feb 24, 2025 | Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block. | ||
| CVE-2025-26526 | Med | 0.00 | 6.5 | 0.00 | Feb 24, 2025 | Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities. | ||
| CVE-2025-26525 | Hig | 0.00 | 8.6 | 0.00 | Feb 24, 2025 | Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed). | ||
| CVE-2024-48900 | Med | 0.00 | 4.3 | 0.00 | Nov 13, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to. | ||
| CVE-2024-43437 | Med | 0.00 | 5.4 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files. | ||
| CVE-2024-43435 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary. | ||
| CVE-2024-43433 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users. | ||
| CVE-2024-43432 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs. | ||
| CVE-2024-43430 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. External API access to Quiz can override contained insufficient access control. | ||
| CVE-2024-43429 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information. | ||
| CVE-2024-43427 | Low | 0.00 | 3.7 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party. | ||
| CVE-2024-43428 | Hig | 0.00 | 7.7 | 0.00 | Nov 7, 2024 | To address a cache poisoning risk in Moodle, additional validation for local storage was required. | ||
| CVE-2024-43426 | Hig | 0.00 | 7.5 | 0.01 | Nov 7, 2024 | A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed. | ||
| CVE-2024-34009 | Hig | 0.00 | 7.5 | 0.00 | May 31, 2024 | Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized. | ||
| CVE-2024-34007 | Hig | 0.00 | 8.8 | 0.00 | May 31, 2024 | The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF. | ||
| CVE-2024-34003 | Med | 0.00 | 5.9 | 0.00 | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include. |
- risk 0.18cvss 3.8epss 0.01
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.
- risk 0.18cvss 2.7epss 0.01
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
- risk 0.16cvss 3.5epss 0.00
A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could…
- risk 0.16cvss 3.5epss 0.00
A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.
- risk 0.16cvss 3.5epss 0.01
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
- risk 0.14cvss 3.3epss 0.00
Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
- risk 0.14cvss 3.3epss 0.01
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
- risk 0.14cvss 3.3epss 0.00
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
- risk 0.14cvss 3.3epss 0.01
The course upload preview contained an XSS risk for users uploading unsafe data.
- risk 0.14cvss 3.3epss 0.01
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
- risk 0.14cvss 3.3epss 0.00
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
- risk 0.14cvss 3.3epss 0.01
The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.
- risk 0.13cvss 3.1epss 0.00
A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and…
- risk 0.13cvss 3.1epss 0.01
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
- risk 0.10cvss 8.1epss 0.88
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
- CVE-2013-3630Nov 1, 2013risk 0.06cvss —epss 0.43
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
- risk 0.04cvss 7.5epss 0.49
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to…
- risk 0.04cvss 6.1epss 0.14
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by…
- CVE-2006-0147Jan 9, 2006risk 0.04cvss —epss 0.13
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote…
- CVE-2006-0146Jan 9, 2006risk 0.04cvss —epss 0.13
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to…
- CVE-2009-1171Mar 30, 2009risk 0.03cvss —epss 0.06
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.
- CVE-2007-6538Dec 27, 2007risk 0.03cvss —epss 0.04
SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2007-1647Mar 24, 2007risk 0.03cvss —epss 0.03
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session…
- CVE-2006-5219Oct 10, 2006risk 0.03cvss —epss 0.02
SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.
- CVE-2006-3951Aug 1, 2006risk 0.03cvss —epss 0.03
PHP remote file inclusion vulnerability in moodle.php in Mam-moodle alpha component (com_moodle) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
- CVE-2004-1978Apr 30, 2004risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.
- risk 0.01cvss 9.8epss 0.09
The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this…
- CVE-2008-1502Mar 25, 2008risk 0.01cvss —epss 0.10
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing…
- risk 0.00cvss 5.3epss 0.00
A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.
- risk 0.00cvss 3.1epss 0.00
Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.
- risk 0.00cvss 3.1epss 0.00
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
- risk 0.00cvss 8.3epss 0.00
The question bank filter required additional sanitizing to prevent a reflected XSS risk.
- risk 0.00cvss 8.3epss 0.01
Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.
- risk 0.00cvss 3.4epss 0.00
The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
- risk 0.00cvss 5.3epss 0.00
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
- risk 0.00cvss 6.5epss 0.00
Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.
- risk 0.00cvss 8.6epss 0.00
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).
- risk 0.00cvss 4.3epss 0.00
A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.
- risk 0.00cvss 5.4epss 0.00
A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.
- risk 0.00cvss 3.7epss 0.00
A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party.
- risk 0.00cvss 7.7epss 0.00
To address a cache poisoning risk in Moodle, additional validation for local storage was required.
- risk 0.00cvss 7.5epss 0.01
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
- risk 0.00cvss 7.5epss 0.00
Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.
- risk 0.00cvss 8.8epss 0.00
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
- risk 0.00cvss 5.9epss 0.00
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
Page 7 of 13