Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2023-35133
An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1…
Moodle
3.9.22 / 3.11.15+
MEDIUM 6.3
CVE-2023-35132
A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3…
Moodle
3.9.22 / 3.11.15+
MEDIUM 6.1
CVE-2023-35131
Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 a…
Moodle
3.11.15 / 4.0.9+
MEDIUM 5.4
CVE-2021-27131
Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" v…
Moodle
No fix yet
HIGH 7.3
CVE-2023-30944
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A r…
Moodle
3.9.21 / 3.11.14+
MEDIUM 5.3
CVE-2023-30943EPSS 7%
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A re…
Moodle
4.1.3+
CRITICAL 9.8
CVE-2023-28333
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploi…
Moodle
3.9.20 / 3.11.13+
HIGH 8.8
CVE-2023-28335
The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.
Moodle
Patch available
MEDIUM 6.1
CVE-2023-28331
Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
Moodle
3.9.20 / 3.11.13+
MEDIUM 6.1
CVE-2023-28332
If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.
Moodle
3.9.20 / 3.11.13+
HIGH 8.8
CVE-2023-28329
Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers…
Moodle
3.9.20 / 3.11.13+
MEDIUM 6.5
CVE-2023-28330
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, manag…
Moodle
3.9.20 / 3.11.13+
MEDIUM 5.3
CVE-2021-36402
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.
Moodle
3.9.8 / 3.10.5+
MEDIUM 5.3
CVE-2021-36403
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a p…
Moodle
3.9.8 / 3.10.5+
MEDIUM 5.4
CVE-2021-36398
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
Moodle
Patch available
MEDIUM 5.4
CVE-2021-36399
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
Moodle
Patch available
MEDIUM 5.3
CVE-2021-36397
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
Moodle
3.9.8 / 3.10.5+
MEDIUM 5.3
CVE-2021-36400
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
Moodle
3.9.8 / 3.10.5+
CRITICAL 9.8
CVE-2021-36392
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
Moodle
3.9.8 / 3.10.5+
CRITICAL 9.8
CVE-2021-36393EPSS 52%
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
Moodle
3.9.8 / 3.10.5+
CRITICAL 9.8
CVE-2021-36394EPSS 7%
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
Moodle
3.9.8 / 3.10.5+
HIGH 7.5
CVE-2021-36395
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.
Moodle
3.9.8 / 3.10.5+
HIGH 7.5
CVE-2021-36396
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF…
Moodle
3.9.8 / 3.10.5+
HIGH 8.2
CVE-2023-23923
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that prefer…
Moodle
3.9.19 / 3.11.12+
MEDIUM 6.1
CVE-2023-23921
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacke…
Moodle
3.9.19 / 3.11.12+
MEDIUM 6.1
CVE-2023-23922
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick th…
Moodle
4.0.6+
MEDIUM 6.1
CVE-2022-39183
Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
Saml Authentication
Mitigation only
CRITICAL 9.1
CVE-2022-45152
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input …
Moodle
3.9.18 / 3.11.11+
MEDIUM 6.1
CVE-2022-45150
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in p…
Moodle
3.9.18 / 3.11.11+
MEDIUM 5.4
CVE-2022-45149
A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF toke…
Moodle
3.9.18 / 3.11.11+