Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle MEDIUM 6.1
CVE-2019-14884

A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error mess…

Fix: 3.5.9 / 3.6.7+
Fix from $1,600 2020-03-18
Moodle MEDIUM 5.3
CVE-2019-14883

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were n…

Fix: 3.6.7 / 3.7.3+
Fix from $1,600 2020-03-18
Moodle MEDIUM 6.1
CVE-2019-14881

A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.

Fix: 3.7.2+
Fix from $1,600 2020-03-18
Moodle MEDIUM 6.1
CVE-2019-14882

A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.

Fix: after 3.7.3
Fix from $1,600 2020-03-18
Moodle MEDIUM 6.5
CVE-2020-1692

Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

Fix: 3.7.2+
Fix from $1,600 2020-02-17
Moodle MEDIUM 5.4
CVE-2019-18210

Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of…

Fix: after 3.7.2
Fix from $1,600 2020-02-11
Moodle MEDIUM 5.4
CVE-2019-14879

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed…

Fix: after 3.7.2
Fix from $1,600 2020-01-07
Moodle HIGH 7.5
CVE-2012-1170

Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough

Fix: 2.2.2+
Fix from $1,950 2019-11-14
Moodle MEDIUM 5.3
CVE-2012-1169

Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are show…

Fix: 2.2.2+
Fix from $1,600 2019-11-14
Moodle HIGH 8.2
CVE-2012-1168

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.

Fix: 2.2.2+
Fix from $1,950 2019-11-14
Moodle HIGH 7.5
CVE-2012-1155

Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from …

Fix: 1.9.17 / 2.0.8+
Fix from $1,950 2019-11-14
Moodle HIGH 7.5
CVE-2012-1156

Moodle before 2.2.2 has users' private files included in course backups

Fix: 2.2.2+
Fix from $1,950 2019-11-14
Moodle HIGH 8.8
CVE-2019-10186

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.

Fix: 3.5.7 / 3.6.5+
Fix from $1,950 2019-07-31
Moodle HIGH 7.5
CVE-2019-10154

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

Fix: 3.6.4+
Fix from $1,950 2019-06-26
Moodle MEDIUM 6.1
CVE-2019-10133

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricte…

Fix: after 3.6.3
Fix from $1,600 2019-06-26
Moodle HIGH 8.8
CVE-2019-3849

A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content…

Fix: 3.4.8 / 3.5.5+
Fix from $1,950 2019-03-26
Moodle MEDIUM 6.1
CVE-2019-3850

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (…

Fix: 3.1.17 / 3.4.8+
Fix from $1,600 2019-03-26
Moodle CRITICAL 10.0
CVE-2019-3809

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, w…

Fix: after 3.1.15
Fix from $2,300 2019-03-25
Moodle MEDIUM 6.1
CVE-2019-3810EPSS 14%

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did …

Fix: after 3.6.1
Fix from $1,600 2019-03-25
Moodle MEDIUM 5.4
CVE-2019-3808

A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' cap…

Fix: after 3.5.3
Fix from $1,600 2019-03-25
Moodle HIGH 7.5
CVE-2019-6970

Moodle 3.5.x before 3.5.4 allows SSRF.

Fix: 3.5.4+
Fix from $1,950 2019-03-21
Moodle HIGH 8.8
CVE-2018-16854

A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token t…

Fix: 3.1.15 / 3.3.9+
Fix from $1,950 2018-11-26
Moodle MEDIUM 6.1
CVE-2018-14631

moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigat…

Fix: 3.3.8 / 3.4.5+
Fix from $1,600 2018-09-17
Moodle HIGH 8.8
CVE-2018-14630

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When imp…

Fix: 3.1.14 / 3.3.8+
Fix from $1,950 2018-09-17
Moodle HIGH 7.3
CVE-2018-10891

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question previ…

Fix: 3.1.13 / 3.3.7+
Fix from $1,950 2018-07-10
Moodle MEDIUM 5.3
CVE-2018-10889

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details o…

Fix: 3.3.7 / 3.4.4+
Fix from $1,600 2018-07-10
Moodle MEDIUM 5.3
CVE-2018-10890

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidd…

Fix: 3.1.13 / 3.3.7+
Fix from $1,600 2018-07-10
Moodle HIGH 8.8
CVE-2018-1133EPSS 32%

An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval…

Fix: after 3.4.2
Fix from $1,950 2018-05-25
Moodle HIGH 8.1
CVE-2018-1137

An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who a…

Fix: after 3.4.2
Fix from $1,950 2018-05-25
Moodle MEDIUM 6.5
CVE-2018-1134

An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by chan…

Fix: after 3.4.2
Fix from $1,600 2018-05-25