Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle MEDIUM 6.5
CVE-2018-1135

An issue was discovered in Moodle 3.x. Students who posted on forums and exported the posts to portfolios can download any stored Moodle file by chan…

Fix: after 3.4.2
Fix from $1,600 2018-05-25
Moodle HIGH 8.1
CVE-2018-1082

A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspende…

Fix: after 3.4.1
Fix from $1,950 2018-04-04
Moodle MEDIUM 5.3
CVE-2018-1081

A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigge…

Fix: after 3.4.1
Fix from $1,600 2018-04-04
Moodle MEDIUM 6.5
CVE-2018-1042EPSS 16%

Moodle 3.x has Server Side Request Forgery in the filepicker.

Fix: after 3.1.9
Fix from $1,600 2018-01-22
Moodle MEDIUM 6.5
CVE-2018-1043

In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.

Mitigation only
Fix from $1,600 2018-01-22
Moodle MEDIUM 5.4
CVE-2018-1045

In Moodle 3.x, there is XSS via a calendar event name.

Fix: after 3.1.9
Fix from $1,600 2018-01-22
Moodle MEDIUM 6.1
CVE-2017-12156

Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

Patch available
Fix from $1,600 2017-09-18
Moodle MEDIUM 6.5
CVE-2017-2642

Moodle 3.x has user fullname disclosure on the user preferences page.

Patch available
Fix from $1,600 2017-07-17
Moodle MEDIUM 6.5
CVE-2017-7532

In Moodle 3.x, course creators are able to change system default settings for courses.

Patch available
Fix from $1,600 2017-07-17
Moodle MEDIUM 6.3
CVE-2017-7489

In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.

Patch available
Fix from $1,600 2017-05-15
Moodle MEDIUM 5.3
CVE-2017-7490

In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.

Patch available
Fix from $1,600 2017-05-15
Moodle HIGH 8.8
CVE-2016-3734

Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.…

Patch available
Fix from $1,950 2017-04-20
Moodle MEDIUM 6.5
CVE-2016-3729

The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated…

Mitigation only
Fix from $1,600 2017-04-20
Moodle MEDIUM 5.3
CVE-2016-3731

Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussion…

Mitigation only
Fix from $1,600 2017-04-20
Moodle MEDIUM 5.4
CVE-2017-7298

In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.

No fix yet
Fix from $1,600 2017-03-29
Moodle CRITICAL 9.8
CVE-2017-2641EPSS 15%

In Moodle 2.x and 3.x, SQL injection can occur via user preferences.

Patch available
Fix from $2,300 2017-03-26
Moodle MEDIUM 6.1
CVE-2017-2644

In Moodle 3.x, XSS can occur via evidence of prior learning.

Patch available
Fix from $1,600 2017-03-26
Moodle MEDIUM 6.1
CVE-2017-2645

In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.

Patch available
Fix from $1,600 2017-03-26
Moodle MEDIUM 5.3
CVE-2017-2643

In Moodle 3.2.x, global search displays user names for unauthenticated users.

Patch available
Fix from $1,600 2017-03-26
Moodle HIGH 7.3
CVE-2016-7038

In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.

Fix: after 2.7.15
Fix from $1,950 2017-01-20
Moodle MEDIUM 6.1
CVE-2017-2578

In Moodle 3.x, there is XSS in the assignment submission page.

Patch available
Fix from $1,600 2017-01-20
Moodle MEDIUM 5.4
CVE-2016-5013

In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.

Fix: after 2.7.14
Fix from $1,600 2017-01-20
Moodle MEDIUM 5.4
CVE-2016-5014

In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.

Patch available
Fix from $1,600 2017-01-20
Moodle MEDIUM 5.3
CVE-2016-5012

In Moodle 3.x, glossary search displays entries without checking user permissions to view them.

Patch available
Fix from $1,600 2017-01-20
Moodle MEDIUM 5.3
CVE-2016-8642

In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.

Fix: after 2.7.16
Fix from $1,600 2017-01-20
Moodle MEDIUM 5.3
CVE-2016-8644

In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.

Fix: after 2.7.16
Fix from $1,600 2017-01-20
Moodle MEDIUM 5.3
CVE-2017-2576

In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.

Fix: after 2.7.17
Fix from $1,600 2017-01-20
Moodle MEDIUM 6.1
CVE-2016-9188

Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_a…

Fix: after 3.1.2
Fix from $1,600 2016-11-04
Moodle HIGH 8.8
CVE-2016-9187

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to exe…

Fix: after 3.1.2
Fix from $1,950 2016-11-04
Moodle HIGH 8.8
CVE-2016-9186

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to e…

Fix: after 3.1.2
Fix from $1,950 2016-11-04