Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle MEDIUM 6.1
CVE-2022-50943

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads…

Fix: after 4.0.0
Fix from $1,600 2026-05-10
Moodle HIGH 7.2
CVE-2026-26046

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command in…

Fix: 4.5.9 / 5.0.5+
Fix from $1,950 2026-02-21
Moodle MEDIUM 6.5
CVE-2026-26047

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution tim…

Fix: 4.5.9 / 5.0.5+
Fix from $1,600 2026-02-21
Moodle HIGH 7.2
CVE-2026-26045

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If…

Fix: 4.5.9 / 5.0.5+
Fix from $1,950 2026-02-21
Moodle MEDIUM 5.3
CVE-2025-67857

A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows u…

Fix: 4.1.21 / 4.4.11+
Fix from $1,600 2026-02-03
Moodle CRITICAL 9.8
CVE-2025-67856

A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges…

Fix: 4.1.22 / 4.4.12+
Fix from $2,300 2026-02-03
Moodle HIGH 7.8
CVE-2025-67851

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker coul…

Fix: 4.1.22 / 4.4.11+
Fix from $1,950 2026-02-03
Moodle HIGH 7.5
CVE-2025-67853

A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allo…

Fix: 4.1.22 / 4.4.11+
Fix from $1,950 2026-02-03
Moodle MEDIUM 6.1
CVE-2025-67849

A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers t…

Fix: 4.5.8 / 5.0.4+
Fix from $1,600 2026-02-03
Moodle MEDIUM 6.1
CVE-2025-67850

A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the f…

Fix: 4.1.22 / 4.4.11+
Fix from $1,600 2026-02-03
Moodle MEDIUM 6.1
CVE-2025-67852

A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled …

Fix: 4.1.22 / 4.4.11+
Fix from $1,600 2026-02-03
Moodle MEDIUM 6.1
CVE-2025-67855

A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This…

Fix: 4.1.22 / 4.4.11+
Fix from $1,600 2026-02-03
Moodle HIGH 8.1
CVE-2025-67848

A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperabili…

Fix: 4.1.22 / 4.4.11+
Fix from $1,950 2026-02-03
Moodle HIGH 8.8
CVE-2025-67847

A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to in…

Fix: 4.1.22 / 4.4.12+
Fix from $1,950 2026-01-23
Moodle MEDIUM 6.1
CVE-2021-47857

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious…

No fix yet
Fix from $1,600 2026-01-21
Moodle HIGH 7.5
CVE-2025-62399

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-f…

Fix: 4.1.21 / 4.4.11+
Fix from $1,950 2025-10-23
Moodle MEDIUM 6.5
CVE-2025-62400

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal priv…

Fix: 4.1.21 / 4.4.11+
Fix from $1,600 2025-10-23
Moodle MEDIUM 5.4
CVE-2025-62398

A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially co…

Fix: 4.4.11 / 4.5.7+
Fix from $1,600 2025-10-23
Moodle MEDIUM 5.3
CVE-2025-62397

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

Fix: 5.0.3+
Fix from $1,600 2025-10-23
Moodle MEDIUM 5.3
CVE-2025-62396

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers we…

Fix: 4.5.7 / 5.0.3+
Fix from $1,600 2025-10-23
Moodle HIGH 8.8
CVE-2025-3642

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to …

Fix: 4.1.18 / 4.3.12+
Fix from $1,950 2025-04-25
Moodle MEDIUM 5.4
CVE-2025-3643

A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.

Fix: 4.1.18 / 4.3.12+
Fix from $1,600 2025-04-25
Moodle HIGH 8.8
CVE-2025-3638

A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request fo…

Fix: 4.1.18 / 4.3.12+
Fix from $1,950 2025-04-25
Moodle HIGH 8.8
CVE-2025-3641

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to …

Fix: 4.1.18 / 4.3.12+
Fix from $1,950 2025-04-25
Moodle HIGH 7.5
CVE-2025-32044

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact infor…

Fix: 4.5.3+
Fix from $1,950 2025-04-25
Moodle HIGH 7.1
CVE-2025-3625

A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from…

Fix: 4.3.12 / 4.4.8+
Fix from $1,950 2025-04-25
Moodle MEDIUM 5.3
CVE-2025-32045

A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to…

Fix: 4.1.17 / 4.3.11+
Fix from $1,600 2025-04-25
Moodle CRITICAL 9.8
CVE-2025-26533

An SQL injection risk was identified in the module list filter within course search.

Fix: 4.1.16 / 4.3.10+
Fix from $2,300 2025-02-24
Moodle HIGH 8.6
CVE-2025-26525

Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with T…

Fix: 4.1.16 / 4.3.10+
Fix from $1,950 2025-02-24
Moodle MEDIUM 6.5
CVE-2025-26526

Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.

Fix: 4.1.16 / 4.3.10+
Fix from $1,600 2025-02-24