Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle MEDIUM 6.1
CVE-2025-26528

The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.

Fix: 4.1.16 / 4.3.10+
Fix from $1,600 2025-02-24
Moodle MEDIUM 6.1
CVE-2025-26529

Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.

Fix: 4.1.16 / 4.3.10+
Fix from $1,600 2025-02-24
Moodle MEDIUM 6.1
CVE-2025-26530

The question bank filter required additional sanitizing to prevent a reflected XSS risk.

Fix: 4.3.10 / 4.4.6+
Fix from $1,600 2025-02-24
Moodle MEDIUM 5.3
CVE-2025-26527

Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.

Fix: 4.1.16 / 4.3.10+
Fix from $1,600 2025-02-24
Moodle MEDIUM 5.3
CVE-2025-26531

Insufficient capability checks made it possible to disable badges a user does not have permission to access.

Fix: 4.1.16 / 4.3.10+
Fix from $1,600 2025-02-24
Moodle HIGH 7.5
CVE-2024-45690

A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

Fix: 4.1.13 / 4.2.10+
Fix from $1,950 2024-11-20
Moodle MEDIUM 6.5
CVE-2024-45689

A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they…

Fix: 4.1.13 / 4.2.10+
Fix from $1,600 2024-11-20
Moodle MEDIUM 5.4
CVE-2024-45691

A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a…

Fix: 4.1.13 / 4.2.10+
Fix from $1,600 2024-11-20
Moodle MEDIUM 6.1
CVE-2024-43439

A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.

Fix: 4.1.12 / 4.2.9+
Fix from $1,600 2024-11-11
Moodle MEDIUM 6.1
CVE-2024-43437

A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from maliciou…

Fix: 4.1.12 / 4.2.9+
Fix from $1,600 2024-11-11
Moodle MEDIUM 5.3
CVE-2024-43430

A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.

Fix: 4.4.2+
Fix from $1,600 2024-11-11
Moodle MEDIUM 5.3
CVE-2024-43432

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original requ…

Fix: 4.1.12 / 4.2.9+
Fix from $1,600 2024-11-11
Moodle MEDIUM 5.3
CVE-2024-43433

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

Fix: 4.3.6 / 4.4.2+
Fix from $1,600 2024-11-11
Moodle MEDIUM 5.3
CVE-2024-43435

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them in…

Fix: 4.1.12 / 4.2.9+
Fix from $1,600 2024-11-11
Moodle MEDIUM 5.3
CVE-2024-43429

A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden us…

Fix: 4.1.12 / 4.2.9+
Fix from $1,600 2024-11-11
Moodle HIGH 8.1
CVE-2024-43434

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerabil…

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Moodle HIGH 7.5
CVE-2024-43438

A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users…

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Moodle HIGH 7.5
CVE-2024-43440

A flaw was found in moodle. A local file may include risks when restoring block backups.

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Moodle HIGH 7.2
CVE-2024-43436

A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Moodle HIGH 8.1
CVE-2024-43425EPSS 83%

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requi…

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Moodle HIGH 7.5
CVE-2024-43426

A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is avail…

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Moodle HIGH 7.5
CVE-2024-43431

A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Moodle HIGH 7.1
CVE-2024-43428

To address a cache poisoning risk in Moodle, additional validation for local storage was required.

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Virtual Programming Lab MEDIUM 6.1
CVE-2024-34312

Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.

Fix: 4.2.3+
Fix from $1,600 2024-06-24
Moodle MEDIUM 5.5
CVE-2024-37674

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a ne…

No fix yet
Fix from $1,600 2024-06-20
Moodle MEDIUM 5.4
CVE-2024-38277

A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.

Fix: 4.1.11 / 4.2.8+
Fix from $1,600 2024-06-18
Moodle HIGH 7.5
CVE-2024-38275

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintent…

Fix: 4.1.11 / 4.2.8+
Fix from $1,950 2024-06-18
Moodle MEDIUM 6.1
CVE-2024-38274

Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.

Fix: 4.1.11 / 4.2.8+
Fix from $1,600 2024-06-18
Moodle MEDIUM 5.4
CVE-2024-38273

Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.

Fix: 4.1.11 / 4.2.8+
Fix from $1,600 2024-06-18
Moodle HIGH 8.8
CVE-2024-34007

The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

Fix: 4.3.4+
Fix from $1,950 2024-05-31