Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle HIGH 8.8
CVE-2024-34008

Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.

Fix: 4.1.10 / 4.2.7+
Fix from $1,950 2024-05-31
Moodle HIGH 7.5
CVE-2024-34009

Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCA…

Fix: 4.3.4+
Fix from $1,950 2024-05-31
Moodle MEDIUM 6.5
CVE-2024-34002

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedba…

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31
Moodle MEDIUM 6.5
CVE-2024-34004

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki m…

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31
Moodle MEDIUM 6.5
CVE-2024-34005

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore databa…

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31
Moodle MEDIUM 5.9
CVE-2024-34003

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore worksh…

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31
Moodle HIGH 8.4
CVE-2024-34001

Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

Fix: 4.1.10 / 4.2.7+
Fix from $1,950 2024-05-31
Moodle CRITICAL 9.8
CVE-2024-33999

The referrer URL used by MFA required additional sanitizing, rather than being used directly.

Fix: 4.3.4+
Fix from $2,300 2024-05-31
Moodle MEDIUM 6.2
CVE-2024-33996

Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did …

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31
Moodle MEDIUM 6.1
CVE-2024-33997

Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31
Moodle MEDIUM 5.4
CVE-2024-33998

Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.

Fix: 4.1.10 / 4.2.7+
Fix from $1,600 2024-05-31
Moodle MEDIUM 5.4
CVE-2024-28593

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a per…

Mitigation only
Fix from $1,600 2024-03-22
Moodle MEDIUM 6.1
CVE-2024-29374

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

No fix yet
Fix from $1,600 2024-03-21
Moodle HIGH 8.8
CVE-2024-25982

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

Fix: 4.1.9 / 4.2.6+
Fix from $1,950 2024-02-19
Moodle MEDIUM 5.3
CVE-2024-25980

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only prov…

Fix: 4.1.9 / 4.2.6+
Fix from $1,600 2024-02-19
Moodle MEDIUM 5.3
CVE-2024-25981

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only…

Fix: 4.1.9 / 4.2.6+
Fix from $1,600 2024-02-19
Moodle MEDIUM 5.3
CVE-2024-25983

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise ava…

Fix: 4.1.9 / 4.2.6+
Fix from $1,600 2024-02-19
Moodle HIGH 7.5
CVE-2024-25978

Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

Fix: 4.1.9 / 4.2.6+
Fix from $1,950 2024-02-19
Moodle MEDIUM 5.3
CVE-2024-25979

The URL parameters accepted by forum search were not limited to the allowed parameters.

Fix: 4.1.9 / 4.2.6+
Fix from $1,600 2024-02-19
Moodle CRITICAL 9.8
CVE-2023-5550

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the …

Fix: 3.9.24 / 3.11.17+
Fix from $2,300 2023-11-09
Moodle MEDIUM 6.1
CVE-2023-5547

The course upload preview contained an XSS risk for users uploading unsafe data.

Fix: 3.9.24 / 3.11.17+
Fix from $1,600 2023-11-09
Moodle MEDIUM 5.4
CVE-2023-5546

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

Fix: 4.0.11 / 4.1.6+
Fix from $1,600 2023-11-09
Moodle MEDIUM 5.3
CVE-2023-5548

Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

Fix: 3.9.24 / 3.11.17+
Fix from $1,600 2023-11-09
Moodle MEDIUM 5.3
CVE-2023-5549

Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not hav…

Fix: 3.9.24 / 3.11.17+
Fix from $1,600 2023-11-09
Moodle HIGH 8.8
CVE-2023-5540

A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.

Fix: 3.9.24 / 3.11.17+
Fix from $1,950 2023-11-09
Moodle MEDIUM 6.1
CVE-2023-5541

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

Fix: 3.9.24 / 3.11.17+
Fix from $1,600 2023-11-09
Moodle MEDIUM 5.4
CVE-2023-5544

Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.

Fix: 3.9.24 / 3.11.17+
Fix from $1,600 2023-11-09
Moodle MEDIUM 5.3
CVE-2023-5545

H5P metadata automatically populated the author with the user's username, which could be sensitive information.

Fix: 3.9.24 / 3.11.17+
Fix from $1,600 2023-11-09
Moodle HIGH 8.8
CVE-2023-5539

A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.

Fix: 3.9.24 / 3.11.17+
Fix from $1,950 2023-11-09
Moodle MEDIUM 5.4
CVE-2023-46858

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "S…

No fix yet
Fix from $1,600 2023-10-29