Vulnerability index

Browse CVEs

69 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2021-47857 Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious… Moodle No fix yet Fix from $1,6002026-01-21 MEDIUM 5.5 CVE-2024-37674 Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a ne… Moodle No fix yet Fix from $1,6002024-06-20 MEDIUM 5.4 CVE-2024-28593 The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a per… Moodle Mitigation only Fix from $1,6002024-03-22 MEDIUM 6.1 CVE-2024-29374 A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter. Moodle No fix yet Fix from $1,6002024-03-21 MEDIUM 5.4 CVE-2023-46858 Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "S… Moodle No fix yet Fix from $1,6002023-10-29 MEDIUM 5.4 CVE-2021-27131 Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" v… Moodle No fix yet Fix from $1,6002023-05-16 MEDIUM 6.1 CVE-2022-39183 Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors. Saml Authentication Mitigation only Fix from $1,6002023-01-12 MEDIUM 5.4 CVE-2021-36568 In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type … Moodle No fix yet Fix from $1,6002022-09-13 CRITICAL 9.1 CVE-2021-21809EPSS 24% A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can le… Moodle No fix yet Fix from $2,3002021-06-23 MEDIUM 5.4 CVE-2021-32244 Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field. Moodle No fix yet Fix from $1,6002021-06-16 MEDIUM 6.5 CVE-2018-1043 In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames. Moodle Mitigation only Fix from $1,6002018-01-22 MEDIUM 6.5 CVE-2016-3729 The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated… Moodle Mitigation only Fix from $1,6002017-04-20 MEDIUM 5.3 CVE-2016-3731 Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussion… Moodle Mitigation only Fix from $1,6002017-04-20 MEDIUM 5.4 CVE-2017-7298 In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element. Moodle No fix yet Fix from $1,6002017-03-29 HIGH 7.5 CVE-2016-7919 Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Admini… Moodle No fix yet Fix from $1,9502016-10-28 MEDIUM 6.8 CVE-2015-5332 Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the gu… Moodle Mitigation only Fix from $1,6002016-02-22 MEDIUM 6.1 CVE-2015-3274 Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x be… Moodle Mitigation only Fix from $1,6002016-02-22 HIGH 7.4 CVE-2015-3272 Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.… Moodle Mitigation only Fix from $1,9502016-02-22 MEDIUM 6.5 CVE-2013-1836 Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not properly manage privileges for WebDAV repositories… Moodle Mitigation only Fix from $1,6002013-03-25 MEDIUM 5.5 CVE-2012-6106 calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remot… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 5.0 CVE-2012-6104 blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 5.0 CVE-2012-6105 blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed af… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 6.8 CVE-2012-6103 Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x befo… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 6.4 CVE-2012-6102 lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to rea… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 5.8 CVE-2012-6101 Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect us… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 6.5 CVE-2012-5479 The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute… Moodle Mitigation only Fix from $1,6002012-11-21 MEDIUM 6.4 CVE-2012-5480 The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended rest… Moodle Mitigation only Fix from $1,6002012-11-21 MEDIUM 6.5 CVE-2012-3395 SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote auth… Moodle Mitigation only Fix from $1,6002012-07-23 MEDIUM 5.5 CVE-2012-3392 mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote a… Moodle Mitigation only Fix from $1,6002012-07-23 MEDIUM 5.0 CVE-2012-3394 auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an h… Moodle Mitigation only Fix from $1,6002012-07-23