VYPR

Vendor CVEs

Moodle

All CVEs

646 total · sorted by risk
  • CVE-2022-0333LowJan 25, 2022
    risk 0.18cvss 3.8epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.

  • CVE-2012-1160LowNov 14, 2019
    risk 0.18cvss 2.7epss 0.01

    Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php

  • CVE-2025-67852LowFeb 3, 2026
    risk 0.16cvss 3.5epss 0.00

    A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could…

  • CVE-2025-3635LowApr 25, 2025
    risk 0.16cvss 3.5epss 0.00

    A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.

  • CVE-2024-25983LowFeb 19, 2024
    risk 0.16cvss 3.5epss 0.01

    Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

  • CVE-2023-5551LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.

  • CVE-2023-5549LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.

  • CVE-2023-5548LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

  • CVE-2023-5547LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    The course upload preview contained an XSS risk for users uploading unsafe data.

  • CVE-2023-5545LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    H5P metadata automatically populated the author with the user's username, which could be sensitive information.

  • CVE-2023-5542LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Students in "Only see own membership" groups could see other students in the group, which should be hidden.

  • CVE-2023-5541LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

  • CVE-2025-3637LowApr 25, 2025
    risk 0.13cvss 3.1epss 0.00

    A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and…

  • CVE-2019-10133LowJun 26, 2019
    risk 0.13cvss 3.1epss 0.01

    A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

  • CVE-2024-43425HigNov 7, 2024
    risk 0.10cvss 8.1epss 0.88

    A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

  • CVE-2013-3630Nov 1, 2013
    risk 0.06cvss —epss 0.43

    Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.

  • CVE-2022-35650HigJul 25, 2022
    risk 0.04cvss 7.5epss 0.49

    The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to…

  • CVE-2019-3810MedMar 25, 2019
    risk 0.04cvss 6.1epss 0.14

    A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by…

  • CVE-2006-0147Jan 9, 2006
    risk 0.04cvss —epss 0.13

    Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote…

  • CVE-2006-0146Jan 9, 2006
    risk 0.04cvss —epss 0.13

    The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to…

  • CVE-2009-1171Mar 30, 2009
    risk 0.03cvss —epss 0.06

    The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.

  • CVE-2007-6538Dec 27, 2007
    risk 0.03cvss —epss 0.04

    SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2007-1647Mar 24, 2007
    risk 0.03cvss —epss 0.03

    Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session…

  • CVE-2006-5219Oct 10, 2006
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

  • CVE-2006-3951Aug 1, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in moodle.php in Mam-moodle alpha component (com_moodle) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2004-1978Apr 30, 2004
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.

  • CVE-2022-35649CriJul 25, 2022
    risk 0.01cvss 9.8epss 0.09

    The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this…

  • CVE-2008-1502Mar 25, 2008
    risk 0.01cvss —epss 0.10

    The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing…

  • CVE-2025-32045MedApr 25, 2025
    risk 0.00cvss 5.3epss 0.00

    A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

  • CVE-2025-26532LowFeb 24, 2025
    risk 0.00cvss 3.1epss 0.00

    Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.

  • CVE-2025-26531LowFeb 24, 2025
    risk 0.00cvss 3.1epss 0.00

    Insufficient capability checks made it possible to disable badges a user does not have permission to access.

  • CVE-2025-26530HigFeb 24, 2025
    risk 0.00cvss 8.3epss 0.00

    The question bank filter required additional sanitizing to prevent a reflected XSS risk.

  • CVE-2025-26529HigFeb 24, 2025
    risk 0.00cvss 8.3epss 0.01

    Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.

  • CVE-2025-26528LowFeb 24, 2025
    risk 0.00cvss 3.4epss 0.00

    The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.

  • CVE-2025-26527MedFeb 24, 2025
    risk 0.00cvss 5.3epss 0.00

    Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.

  • CVE-2025-26526MedFeb 24, 2025
    risk 0.00cvss 6.5epss 0.00

    Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.

  • CVE-2025-26525HigFeb 24, 2025
    risk 0.00cvss 8.6epss 0.00

    Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).

  • CVE-2024-48900MedNov 13, 2024
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.

  • CVE-2024-43437MedNov 11, 2024
    risk 0.00cvss 5.4epss 0.00

    A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.

  • CVE-2024-43435MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.

  • CVE-2024-43433MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

  • CVE-2024-43432MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

  • CVE-2024-43430MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.

  • CVE-2024-43429MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.

  • CVE-2024-43427LowNov 11, 2024
    risk 0.00cvss 3.7epss 0.00

    A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party.

  • CVE-2024-43428HigNov 7, 2024
    risk 0.00cvss 7.7epss 0.00

    To address a cache poisoning risk in Moodle, additional validation for local storage was required.

  • CVE-2024-43426HigNov 7, 2024
    risk 0.00cvss 7.5epss 0.01

    A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.

  • CVE-2024-34009HigMay 31, 2024
    risk 0.00cvss 7.5epss 0.00

    Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.

  • CVE-2024-34007HigMay 31, 2024
    risk 0.00cvss 8.8epss 0.00

    The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

  • CVE-2024-34003MedMay 31, 2024
    risk 0.00cvss 5.9epss 0.00

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

Page 7 of 13