Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle MEDIUM 5.4
CVE-2022-45151

The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user pr…

Fix: 3.11.11 / 4.0.5+
Fix from $1,600 2022-11-23
Moodle HIGH 8.8
CVE-2022-2986

Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.

Fix: 3.11.9 / 4.0.3+
Fix from $1,950 2022-10-06
Moodle CRITICAL 9.8
CVE-2022-40314

A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

Fix: 3.9.17 / 3.11.10+
Fix from $2,300 2022-09-30
Moodle CRITICAL 9.8
CVE-2022-40315

A limited SQL injection risk was identified in the "browse list of users" site administration page.

Fix: 3.9.17 / 3.11.10+
Fix from $2,300 2022-09-30
Moodle HIGH 7.1
CVE-2022-40313

Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.

Fix: 3.9.17 / 3.11.10+
Fix from $1,950 2022-09-30
Moodle MEDIUM 6.5
CVE-2021-40693

An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.

Fix: 3.9.10 / 3.10.7+
Fix from $1,600 2022-09-29
Moodle MEDIUM 5.4
CVE-2021-36568

In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type …

No fix yet
Fix from $1,600 2022-09-13
Moodle HIGH 8.8
CVE-2020-14321EPSS 16%

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.

Fix: 3.5.13 / 3.7.7+
Fix from $1,950 2022-08-16
Moodle HIGH 7.5
CVE-2020-14322

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of ser…

Fix: 3.5.13 / 3.7.7+
Fix from $1,950 2022-08-16
Moodle HIGH 7.2
CVE-2020-1756

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

Fix: 3.5.11 / 3.6.9+
Fix from $1,950 2022-08-16
Moodle MEDIUM 6.1
CVE-2020-14320

In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.

Fix: 3.7.7 / 3.8.4+
Fix from $1,600 2022-08-16
Moodle MEDIUM 5.3
CVE-2020-1755

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

Fix: 3.5.11 / 3.6.9+
Fix from $1,600 2022-08-16
Moodle MEDIUM 5.4
CVE-2020-1691

In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

Patch available
Fix from $1,600 2022-08-05
Moodle CRITICAL 9.8
CVE-2022-35649EPSS 8%

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results i…

Fix: 3.9.15 / 3.11.8+
Fix from $2,300 2022-07-25
Moodle HIGH 7.5
CVE-2022-35650EPSS 49%

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in…

Fix: 3.9.15 / 3.11.8+
Fix from $1,950 2022-07-25
Moodle MEDIUM 6.1
CVE-2022-35651

A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track detai…

Fix: 3.9.15 / 3.11.8+
Fix from $1,600 2022-07-25
Moodle MEDIUM 6.1
CVE-2022-35652

An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can cre…

Fix: 3.9.15 / 3.11.8+
Fix from $1,600 2022-07-25
Moodle MEDIUM 6.1
CVE-2022-35653

A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in …

Fix: 3.9.15 / 3.11.8+
Fix from $1,600 2022-07-25
Moodle CRITICAL 9.8
CVE-2022-30599

A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.

Fix: 3.9.14 / 3.10.11+
Fix from $2,300 2022-05-18
Moodle CRITICAL 9.8
CVE-2022-30600EPSS 5%

A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

Fix: 3.9.14 / 3.10.11+
Fix from $2,300 2022-05-18
Moodle MEDIUM 5.3
CVE-2022-30597

A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.

Fix: 3.9.14 / 3.10.11+
Fix from $1,600 2022-05-18
Moodle MEDIUM 5.4
CVE-2022-30596

A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored …

Fix: 3.9.14 / 3.10.11+
Fix from $1,600 2022-05-18
Moodle HIGH 8.8
CVE-2022-0983

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and m…

Fix: 3.9.13 / 3.10.10+
Fix from $1,950 2022-03-25
Moodle MEDIUM 6.1
CVE-2021-32478

The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 t…

Fix: 3.8.9 / 3.9.7+
Fix from $1,600 2022-03-11
Moodle HIGH 7.5
CVE-2021-32476

A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.…

Fix: 3.5.18 / 3.8.9+
Fix from $1,950 2022-03-11
Moodle MEDIUM 5.4
CVE-2021-32475

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8…

Fix: 3.5.18 / 3.8.9+
Fix from $1,600 2022-03-11
Moodle HIGH 7.2
CVE-2021-32474

An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required si…

Fix: 3.5.18 / 3.8.9+
Fix from $1,950 2022-03-11
Moodle MEDIUM 5.3
CVE-2021-32473

It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.…

Fix: 3.5.18 / 3.8.9+
Fix from $1,600 2022-03-11
Moodle CRITICAL 9.8
CVE-2022-0332EPSS 45%

A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching …

Fix: 3.11.5+
Fix from $2,300 2022-01-25
Moodle HIGH 8.8
CVE-2022-0335

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" f…

Fix: 3.9.12 / 3.10.9+
Fix from $1,950 2022-01-25