Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle HIGH 8.8
CVE-2021-43559

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" fun…

Fix: 3.9.11 / 3.10.8+
Fix from $1,950 2021-11-22
Moodle MEDIUM 6.1
CVE-2021-43558

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetyp…

Fix: 3.9.11 / 3.10.8+
Fix from $1,600 2021-11-22
Moodle MEDIUM 5.3
CVE-2021-43560

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks…

Fix: 3.9.11 / 3.10.8+
Fix from $1,600 2021-11-22
Moodle CRITICAL 9.8
CVE-2021-3943

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk w…

Fix: after 3.11.3
Fix from $2,300 2021-11-22
Moodle CRITICAL 9.1
CVE-2021-21809EPSS 24%

A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can le…

No fix yet
Fix from $2,300 2021-06-23
Moodle MEDIUM 5.4
CVE-2021-32244

Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.

No fix yet
Fix from $1,600 2021-06-16
Moodle MEDIUM 6.1
CVE-2019-14827

A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustach…

Fix: after 3.7.1
Fix from $1,600 2021-05-17
Moodle MEDIUM 6.1
CVE-2019-14830

A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint conta…

Fix: after 3.7.1
Fix from $1,600 2021-03-19
Moodle MEDIUM 6.1
CVE-2019-14831

A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained a…

Fix: after 3.7.1
Fix from $1,600 2021-03-19
Moodle MEDIUM 5.4
CVE-2021-20279

The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

Fix: 3.5.17 / 3.8.8+
Fix from $1,600 2021-03-15
Moodle MEDIUM 5.4
CVE-2021-20280

Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

Fix: 3.5.17 / 3.8.8+
Fix from $1,600 2021-03-15
Moodle MEDIUM 5.3
CVE-2021-20281

It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5,…

Fix: 3.5.17 / 3.8.8+
Fix from $1,600 2021-03-15
Moodle MEDIUM 5.3
CVE-2021-20282

When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10…

Fix: 3.5.17 / 3.8.8+
Fix from $1,600 2021-03-15
Moodle MEDIUM 5.3
CVE-2021-20185

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which co…

Fix: 3.5.16 / 3.8.7+
Fix from $1,600 2021-01-28
Moodle HIGH 7.2
CVE-2021-20187

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts v…

Fix: 3.5.16 / 3.8.7+
Fix from $1,950 2021-01-28
Moodle MEDIUM 5.4
CVE-2021-20183

It was found in Moodle before version 3.10.1 that some search inputs were vulnerable to reflected XSS due to insufficient escaping of search queries.

Fix: 3.10.1+
Fix from $1,600 2021-01-28
Moodle MEDIUM 5.4
CVE-2021-20186

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX conte…

Fix: 3.5.16 / 3.8.7+
Fix from $1,600 2021-01-28
Moodle MEDIUM 6.1
CVE-2020-25627

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

Fix: 3.9.2+
Fix from $1,600 2020-12-09
Moodle MEDIUM 6.1
CVE-2020-25631

A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapter title…

Fix: 3.7.8 / 3.8.5+
Fix from $1,600 2020-12-08
Moodle HIGH 8.8
CVE-2020-25629

A vulnerability was found in Moodle where users with "Log in as" capability in a course context (typically, course managers) may gain access to some …

Fix: 3.5.14 / 3.7.8+
Fix from $1,950 2020-12-08
Moodle HIGH 7.5
CVE-2020-25630

A vulnerability was found in Moodle where the decompressed size of zip files was not checked against available user quota before unzipping them, whic…

Fix: 3.5.14 / 3.7.8+
Fix from $1,950 2020-12-08
Moodle MEDIUM 6.1
CVE-2020-25628

The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7.7, 3.5 t…

Fix: 3.5.14 / 3.7.8+
Fix from $1,600 2020-12-08
Moodle MEDIUM 5.3
CVE-2020-25703

The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affec…

Fix: after 3.9.2
Fix from $1,600 2020-11-19
Moodle HIGH 7.5
CVE-2020-25698

Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them …

Fix: after 3.9.2
Fix from $1,950 2020-11-19
Moodle HIGH 7.5
CVE-2020-25699

In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that …

Fix: after 3.9.2
Fix from $1,950 2020-11-19
Moodle MEDIUM 6.5
CVE-2020-25700

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3…

Fix: after 3.9.2
Fix from $1,600 2020-11-19
Moodle MEDIUM 6.1
CVE-2020-25702

In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 an…

Fix: 3.9.3+
Fix from $1,600 2020-11-19
Moodle MEDIUM 5.3
CVE-2020-25701

If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneousl…

Fix: after 3.9.2
Fix from $1,600 2020-11-19
Moodle HIGH 8.8
CVE-2020-10738

A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was…

Fix: 3.5.12 / 3.6.10+
Fix from $1,950 2020-05-21
Moodle CRITICAL 9.1
CVE-2019-14880

A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 providers who do not verify us…

Fix: 3.5.9 / 3.6.7+
Fix from $2,300 2020-03-31