Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle HIGH 7.5
CVE-2016-7919

Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Admini…

No fix yet
Fix from $1,950 2016-10-28
Moodle MEDIUM 5.3
CVE-2016-2190

Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which a…

Fix: after 2.6.11
Fix from $1,600 2016-05-22
Moodle HIGH 8.8
CVE-2016-2157

Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.…

Fix: after 2.6.11
Fix from $1,950 2016-05-22
Moodle MEDIUM 6.1
CVE-2016-2153

Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.1…

Fix: after 2.6.11
Fix from $1,600 2016-05-22
Moodle MEDIUM 6.1
CVE-2016-2152

Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x bef…

Fix: after 2.6.11
Fix from $1,600 2016-05-22
Moodle HIGH 8.8
CVE-2015-5338

Multiple cross-site request forgery (CSRF) vulnerabilities in the lesson module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, an…

Fix: after 2.6.11
Fix from $1,950 2016-02-22
Moodle MEDIUM 6.1
CVE-2015-5337

Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly restrict the availability of Flowplayer, whi…

Fix: after 2.6.11
Fix from $1,600 2016-02-22
Moodle MEDIUM 5.4
CVE-2015-5336

Multiple cross-site scripting (XSS) vulnerabilities in the survey module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x…

Fix: after 2.6.11
Fix from $1,600 2016-02-22
Moodle MEDIUM 6.8
CVE-2015-5332

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the gu…

Mitigation only
Fix from $1,600 2016-02-22
Moodle MEDIUM 5.4
CVE-2015-5269

Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.…

Fix: after 2.6.11
Fix from $1,600 2016-02-22
Moodle HIGH 7.5
CVE-2015-5267

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to imp…

Fix: after 2.6.11
Fix from $1,950 2016-02-22
Moodle MEDIUM 6.8
CVE-2015-5266

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 all…

Fix: after 2.6.11
Fix from $1,600 2016-02-22
Moodle MEDIUM 5.4
CVE-2015-5264

The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypa…

Fix: after 2.6.11
Fix from $1,600 2016-02-22
Moodle MEDIUM 6.1
CVE-2015-3275

Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x b…

Fix: after 2.6.11
Fix from $1,600 2016-02-22
Moodle MEDIUM 6.1
CVE-2015-3274

Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x be…

Mitigation only
Fix from $1,600 2016-02-22
Moodle HIGH 7.4
CVE-2015-3272

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.…

Mitigation only
Fix from $1,950 2016-02-22
Moodle MEDIUM 5.8
CVE-2015-3175

Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attacker…

Fix: after 2.5.9
Fix from $1,600 2015-06-01
Moodle MEDIUM 6.8
CVE-2015-2268

filter/urltolink/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users…

Fix: after 2.5.9
Fix from $1,600 2015-06-01
Moodle MEDIUM 6.8
CVE-2015-1493

Directory traversal vulnerability in the min_get_slash_argument function in lib/configonlylib.php in Moodle through 2.5.9, 2.6.x before 2.6.8, 2.7.x …

Fix: after 2.5.9
Fix from $1,600 2015-06-01
Moodle MEDIUM 6.8
CVE-2015-0218

Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.…

Fix: after 2.5.9
Fix from $1,600 2015-06-01
Moodle MEDIUM 6.8
CVE-2015-0217

filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated use…

Fix: after 2.5.9
Fix from $1,600 2015-06-01
Moodle MEDIUM 6.8
CVE-2015-0213

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle thr…

Fix: after 2.5.9
Fix from $1,600 2015-06-01
Moodle MEDIUM 5.0
CVE-2014-9060

The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters use…

Fix: after 2.4.11
Fix from $1,600 2014-11-24
Moodle MEDIUM 5.0
CVE-2014-7848

lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct re…

Fix: after 2.4.11
Fix from $1,600 2014-11-24
Moodle MEDIUM 5.0
CVE-2014-7847

iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote attackers to cause a denial…

Fix: after 2.4.11
Fix from $1,600 2014-11-24
Moodle HIGH 7.5
CVE-2014-7845

The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient…

Fix: after 2.4.11
Fix from $1,950 2014-11-24
Moodle MEDIUM 6.8
CVE-2014-7838

Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and …

Fix: after 2.4.11
Fix from $1,600 2014-11-24
Moodle MEDIUM 5.5
CVE-2014-7837

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remo…

Fix: after 2.4.11
Fix from $1,600 2014-11-24
Moodle MEDIUM 6.8
CVE-2014-7836

Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.…

Fix: after 2.4.11
Fix from $1,600 2014-11-24
Moodle MEDIUM 6.0
CVE-2014-3545

Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to execu…

Patch available
Fix from $1,600 2014-07-29