Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle HIGH 7.5
CVE-2023-35133

An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1…

Fix: 3.9.22 / 3.11.15+
Fix from $1,950 2023-06-22
Moodle MEDIUM 6.3
CVE-2023-35132

A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3…

Fix: 3.9.22 / 3.11.15+
Fix from $1,600 2023-06-22
Moodle MEDIUM 6.1
CVE-2023-35131

Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 a…

Fix: 3.11.15 / 4.0.9+
Fix from $1,600 2023-06-22
Moodle MEDIUM 5.4
CVE-2021-27131

Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" v…

No fix yet
Fix from $1,600 2023-05-16
Moodle HIGH 7.3
CVE-2023-30944

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A r…

Fix: 3.9.21 / 3.11.14+
Fix from $1,950 2023-05-02
Moodle MEDIUM 5.3
CVE-2023-30943EPSS 7%

The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A re…

Fix: 4.1.3+
Fix from $1,600 2023-05-02
Moodle CRITICAL 9.8
CVE-2023-28333

The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploi…

Fix: 3.9.20 / 3.11.13+
Fix from $2,300 2023-03-23
Moodle HIGH 8.8
CVE-2023-28335

The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.

Patch available
Fix from $1,950 2023-03-23
Moodle MEDIUM 6.1
CVE-2023-28331

Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.

Fix: 3.9.20 / 3.11.13+
Fix from $1,600 2023-03-23
Moodle MEDIUM 6.1
CVE-2023-28332

If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.

Fix: 3.9.20 / 3.11.13+
Fix from $1,600 2023-03-23
Moodle HIGH 8.8
CVE-2023-28329

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers…

Fix: 3.9.20 / 3.11.13+
Fix from $1,950 2023-03-23
Moodle MEDIUM 6.5
CVE-2023-28330

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, manag…

Fix: 3.9.20 / 3.11.13+
Fix from $1,600 2023-03-23
Moodle MEDIUM 5.3
CVE-2021-36402

In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.

Fix: 3.9.8 / 3.10.5+
Fix from $1,600 2023-03-06
Moodle MEDIUM 5.3
CVE-2021-36403

In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a p…

Fix: 3.9.8 / 3.10.5+
Fix from $1,600 2023-03-06
Moodle MEDIUM 5.4
CVE-2021-36398

In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.

Patch available
Fix from $1,600 2023-03-06
Moodle MEDIUM 5.4
CVE-2021-36399

In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.

Patch available
Fix from $1,600 2023-03-06
Moodle MEDIUM 5.3
CVE-2021-36397

In Moodle, insufficient capability checks meant message deletions were not limited to the current user.

Fix: 3.9.8 / 3.10.5+
Fix from $1,600 2023-03-06
Moodle MEDIUM 5.3
CVE-2021-36400

In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.

Fix: 3.9.8 / 3.10.5+
Fix from $1,600 2023-03-06
Moodle CRITICAL 9.8
CVE-2021-36392

In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.

Fix: 3.9.8 / 3.10.5+
Fix from $2,300 2023-03-06
Moodle CRITICAL 9.8
CVE-2021-36393EPSS 52%

In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

Fix: 3.9.8 / 3.10.5+
Fix from $2,300 2023-03-06
Moodle CRITICAL 9.8
CVE-2021-36394EPSS 7%

In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

Fix: 3.9.8 / 3.10.5+
Fix from $2,300 2023-03-06
Moodle HIGH 7.5
CVE-2021-36395

In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.

Fix: 3.9.8 / 3.10.5+
Fix from $1,950 2023-03-06
Moodle HIGH 7.5
CVE-2021-36396

In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF…

Fix: 3.9.8 / 3.10.5+
Fix from $1,950 2023-03-06
Moodle HIGH 8.2
CVE-2023-23923

The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that prefer…

Fix: 3.9.19 / 3.11.12+
Fix from $1,950 2023-02-17
Moodle MEDIUM 6.1
CVE-2023-23921

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacke…

Fix: 3.9.19 / 3.11.12+
Fix from $1,600 2023-02-17
Moodle MEDIUM 6.1
CVE-2023-23922

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick th…

Fix: 4.0.6+
Fix from $1,600 2023-02-17
Saml Authentication MEDIUM 6.1
CVE-2022-39183

Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.

Mitigation only
Fix from $1,600 2023-01-12
Moodle CRITICAL 9.1
CVE-2022-45152

A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input …

Fix: 3.9.18 / 3.11.11+
Fix from $2,300 2022-11-25
Moodle MEDIUM 6.1
CVE-2022-45150

A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in p…

Fix: 3.9.18 / 3.11.11+
Fix from $1,600 2022-11-23
Moodle MEDIUM 5.4
CVE-2022-45149

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF toke…

Fix: 3.9.18 / 3.11.11+
Fix from $1,600 2022-11-23