Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2024-34008
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
Moodle
4.1.10 / 4.2.7+
HIGH 7.5
CVE-2024-34009
Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCA…
Moodle
4.3.4+
MEDIUM 6.5
CVE-2024-34002
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedba…
Moodle
4.1.10 / 4.2.7+
MEDIUM 6.5
CVE-2024-34004
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki m…
Moodle
4.1.10 / 4.2.7+
MEDIUM 6.5
CVE-2024-34005
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore databa…
Moodle
4.1.10 / 4.2.7+
MEDIUM 5.9
CVE-2024-34003
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore worksh…
Moodle
4.1.10 / 4.2.7+
HIGH 8.4
CVE-2024-34001
Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
Moodle
4.1.10 / 4.2.7+
CRITICAL 9.8
CVE-2024-33999
The referrer URL used by MFA required additional sanitizing, rather than being used directly.
Moodle
4.3.4+
MEDIUM 6.2
CVE-2024-33996
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did …
Moodle
4.1.10 / 4.2.7+
MEDIUM 6.1
CVE-2024-33997
Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.
Moodle
4.1.10 / 4.2.7+
MEDIUM 5.4
CVE-2024-33998
Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.
Moodle
4.1.10 / 4.2.7+
MEDIUM 5.4
CVE-2024-28593
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a per…
Moodle
Mitigation only
MEDIUM 6.1
CVE-2024-29374
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.
Moodle
No fix yet
HIGH 8.8
CVE-2024-25982
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
Moodle
4.1.9 / 4.2.6+
MEDIUM 5.3
CVE-2024-25980
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only prov…
Moodle
4.1.9 / 4.2.6+
MEDIUM 5.3
CVE-2024-25981
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only…
Moodle
4.1.9 / 4.2.6+
MEDIUM 5.3
CVE-2024-25983
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise ava…
Moodle
4.1.9 / 4.2.6+
HIGH 7.5
CVE-2024-25978
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
Moodle
4.1.9 / 4.2.6+
MEDIUM 5.3
CVE-2024-25979
The URL parameters accepted by forum search were not limited to the allowed parameters.
Moodle
4.1.9 / 4.2.6+
CRITICAL 9.8
CVE-2023-5550
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the …
Moodle
3.9.24 / 3.11.17+
MEDIUM 6.1
CVE-2023-5547
The course upload preview contained an XSS risk for users uploading unsafe data.
Moodle
3.9.24 / 3.11.17+
MEDIUM 5.4
CVE-2023-5546
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
Moodle
4.0.11 / 4.1.6+
MEDIUM 5.3
CVE-2023-5548
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
Moodle
3.9.24 / 3.11.17+
MEDIUM 5.3
CVE-2023-5549
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not hav…
Moodle
3.9.24 / 3.11.17+
HIGH 8.8
CVE-2023-5540
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
Moodle
3.9.24 / 3.11.17+
MEDIUM 6.1
CVE-2023-5541
The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.
Moodle
3.9.24 / 3.11.17+
MEDIUM 5.4
CVE-2023-5544
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
Moodle
3.9.24 / 3.11.17+
MEDIUM 5.3
CVE-2023-5545
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
Moodle
3.9.24 / 3.11.17+
HIGH 8.8
CVE-2023-5539
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
Moodle
3.9.24 / 3.11.17+
MEDIUM 5.4
CVE-2023-46858
Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "S…
Moodle
No fix yet