Vulnerabilities (CVE)

Filtered by vendor Moodle Subscribe
Filtered by product Moodle
Total 605 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-36395 1 Moodle 1 Moodle 2025-03-07 N/A 7.5 HIGH
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.
CVE-2021-36397 1 Moodle 1 Moodle 2025-03-07 N/A 5.3 MEDIUM
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
CVE-2021-36399 1 Moodle 1 Moodle 2025-03-07 N/A 5.4 MEDIUM
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
CVE-2021-36402 1 Moodle 1 Moodle 2025-03-07 N/A 5.3 MEDIUM
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.
CVE-2021-36401 1 Moodle 1 Moodle 2025-03-07 N/A 4.8 MEDIUM
In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.
CVE-2021-36403 1 Moodle 1 Moodle 2025-03-07 N/A 5.3 MEDIUM
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
CVE-2021-36400 1 Moodle 1 Moodle 2025-03-07 N/A 5.3 MEDIUM
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
CVE-2021-36394 1 Moodle 1 Moodle 2025-03-06 N/A 9.8 CRITICAL
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
CVE-2021-36396 1 Moodle 1 Moodle 2025-03-05 N/A 7.5 HIGH
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
CVE-2023-28331 1 Moodle 1 Moodle 2025-02-25 N/A 6.1 MEDIUM
Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
CVE-2022-40208 1 Moodle 1 Moodle 2025-02-20 N/A 4.3 MEDIUM
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.
CVE-2024-25983 2 Fedoraproject, Moodle 2 Fedora, Moodle 2025-01-23 N/A 5.3 MEDIUM
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
CVE-2024-25979 2 Fedoraproject, Moodle 2 Fedora, Moodle 2025-01-23 N/A 5.3 MEDIUM
The URL parameters accepted by forum search were not limited to the allowed parameters.
CVE-2024-25978 2 Fedoraproject, Moodle 2 Fedora, Moodle 2025-01-23 N/A 7.5 HIGH
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
CVE-2024-25980 2 Fedoraproject, Moodle 2 Fedora, Moodle 2025-01-23 N/A 5.3 MEDIUM
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
CVE-2024-25981 2 Fedoraproject, Moodle 2 Fedora, Moodle 2025-01-23 N/A 5.3 MEDIUM
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
CVE-2024-25982 2 Fedoraproject, Moodle 2 Fedora, Moodle 2025-01-23 N/A 8.8 HIGH
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
CVE-2024-48897 1 Moodle 1 Moodle 2024-11-20 N/A 4.3 MEDIUM
A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.
CVE-2024-48896 1 Moodle 1 Moodle 2024-11-20 N/A 4.3 MEDIUM
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.
CVE-2024-48898 1 Moodle 1 Moodle 2024-11-20 N/A 4.3 MEDIUM
A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.