Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2022-50943 Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads… Moodle after 4.0.0 Fix from $1,6002026-05-10 HIGH 7.2 CVE-2026-26046 A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command in… Moodle 4.5.9 / 5.0.5+ Fix from $1,9502026-02-21 MEDIUM 6.5 CVE-2026-26047 A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution tim… Moodle 4.5.9 / 5.0.5+ Fix from $1,6002026-02-21 HIGH 7.2 CVE-2026-26045 A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If… Moodle 4.5.9 / 5.0.5+ Fix from $1,9502026-02-21 MEDIUM 5.3 CVE-2025-67857 A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows u… Moodle 4.1.21 / 4.4.11+ Fix from $1,6002026-02-03 CRITICAL 9.8 CVE-2025-67856 A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges… Moodle 4.1.22 / 4.4.12+ Fix from $2,3002026-02-03 HIGH 7.8 CVE-2025-67851 A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker coul… Moodle 4.1.22 / 4.4.11+ Fix from $1,9502026-02-03 HIGH 7.5 CVE-2025-67853 A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allo… Moodle 4.1.22 / 4.4.11+ Fix from $1,9502026-02-03 MEDIUM 6.1 CVE-2025-67849 A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers t… Moodle 4.5.8 / 5.0.4+ Fix from $1,6002026-02-03 MEDIUM 6.1 CVE-2025-67850 A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the f… Moodle 4.1.22 / 4.4.11+ Fix from $1,6002026-02-03 MEDIUM 6.1 CVE-2025-67852 A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled … Moodle 4.1.22 / 4.4.11+ Fix from $1,6002026-02-03 MEDIUM 6.1 CVE-2025-67855 A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This… Moodle 4.1.22 / 4.4.11+ Fix from $1,6002026-02-03 HIGH 8.1 CVE-2025-67848 A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperabili… Moodle 4.1.22 / 4.4.11+ Fix from $1,9502026-02-03 HIGH 8.8 CVE-2025-67847 A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to in… Moodle 4.1.22 / 4.4.12+ Fix from $1,9502026-01-23 MEDIUM 6.1 CVE-2021-47857 Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious… Moodle No fix yet Fix from $1,6002026-01-21 HIGH 7.5 CVE-2025-62399 Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-f… Moodle 4.1.21 / 4.4.11+ Fix from $1,9502025-10-23 MEDIUM 6.5 CVE-2025-62400 Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal priv… Moodle 4.1.21 / 4.4.11+ Fix from $1,6002025-10-23 MEDIUM 5.4 CVE-2025-62398 A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially co… Moodle 4.4.11 / 4.5.7+ Fix from $1,6002025-10-23 MEDIUM 5.3 CVE-2025-62397 The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance. Moodle 5.0.3+ Fix from $1,6002025-10-23 MEDIUM 5.3 CVE-2025-62396 An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers we… Moodle 4.5.7 / 5.0.3+ Fix from $1,6002025-10-23 HIGH 8.8 CVE-2025-3642 A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to … Moodle 4.1.18 / 4.3.12+ Fix from $1,9502025-04-25 MEDIUM 5.4 CVE-2025-3643 A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk. Moodle 4.1.18 / 4.3.12+ Fix from $1,6002025-04-25 HIGH 8.8 CVE-2025-3638 A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request fo… Moodle 4.1.18 / 4.3.12+ Fix from $1,9502025-04-25 HIGH 8.8 CVE-2025-3641 A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to … Moodle 4.1.18 / 4.3.12+ Fix from $1,9502025-04-25 HIGH 7.5 CVE-2025-32044 A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact infor… Moodle 4.5.3+ Fix from $1,9502025-04-25 HIGH 7.1 CVE-2025-3625 A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from… Moodle 4.3.12 / 4.4.8+ Fix from $1,9502025-04-25 MEDIUM 5.3 CVE-2025-32045 A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to… Moodle 4.1.17 / 4.3.11+ Fix from $1,6002025-04-25 CRITICAL 9.8 CVE-2025-26533 An SQL injection risk was identified in the module list filter within course search. Moodle 4.1.16 / 4.3.10+ Fix from $2,3002025-02-24 HIGH 8.6 CVE-2025-26525 Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with T… Moodle 4.1.16 / 4.3.10+ Fix from $1,9502025-02-24 MEDIUM 6.5 CVE-2025-26526 Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities. Moodle 4.1.16 / 4.3.10+ Fix from $1,6002025-02-24