Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-35133 An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1… Moodle 3.9.22 / 3.11.15+ Fix from $1,9502023-06-22 MEDIUM 6.3 CVE-2023-35132 A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3… Moodle 3.9.22 / 3.11.15+ Fix from $1,6002023-06-22 MEDIUM 6.1 CVE-2023-35131 Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 a… Moodle 3.11.15 / 4.0.9+ Fix from $1,6002023-06-22 MEDIUM 5.4 CVE-2021-27131 Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" v… Moodle No fix yet Fix from $1,6002023-05-16 HIGH 7.3 CVE-2023-30944 The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A r… Moodle 3.9.21 / 3.11.14+ Fix from $1,9502023-05-02 MEDIUM 5.3 CVE-2023-30943EPSS 7% The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A re… Moodle 4.1.3+ Fix from $1,6002023-05-02 CRITICAL 9.8 CVE-2023-28333 The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploi… Moodle 3.9.20 / 3.11.13+ Fix from $2,3002023-03-23 HIGH 8.8 CVE-2023-28335 The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk. Moodle Patch available Fix from $1,9502023-03-23 MEDIUM 6.1 CVE-2023-28331 Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk. Moodle 3.9.20 / 3.11.13+ Fix from $1,6002023-03-23 MEDIUM 6.1 CVE-2023-28332 If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk. Moodle 3.9.20 / 3.11.13+ Fix from $1,6002023-03-23 HIGH 8.8 CVE-2023-28329 Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers… Moodle 3.9.20 / 3.11.13+ Fix from $1,9502023-03-23 MEDIUM 6.5 CVE-2023-28330 Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, manag… Moodle 3.9.20 / 3.11.13+ Fix from $1,6002023-03-23 MEDIUM 5.3 CVE-2021-36402 In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk. Moodle 3.9.8 / 3.10.5+ Fix from $1,6002023-03-06 MEDIUM 5.3 CVE-2021-36403 In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a p… Moodle 3.9.8 / 3.10.5+ Fix from $1,6002023-03-06 MEDIUM 5.4 CVE-2021-36398 In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk. Moodle Patch available Fix from $1,6002023-03-06 MEDIUM 5.4 CVE-2021-36399 In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk. Moodle Patch available Fix from $1,6002023-03-06 MEDIUM 5.3 CVE-2021-36397 In Moodle, insufficient capability checks meant message deletions were not limited to the current user. Moodle 3.9.8 / 3.10.5+ Fix from $1,6002023-03-06 MEDIUM 5.3 CVE-2021-36400 In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. Moodle 3.9.8 / 3.10.5+ Fix from $1,6002023-03-06 CRITICAL 9.8 CVE-2021-36392 In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. Moodle 3.9.8 / 3.10.5+ Fix from $2,3002023-03-06 CRITICAL 9.8 CVE-2021-36393EPSS 52% In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. Moodle 3.9.8 / 3.10.5+ Fix from $2,3002023-03-06 CRITICAL 9.8 CVE-2021-36394EPSS 7% In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. Moodle 3.9.8 / 3.10.5+ Fix from $2,3002023-03-06 HIGH 7.5 CVE-2021-36395 In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service. Moodle 3.9.8 / 3.10.5+ Fix from $1,9502023-03-06 HIGH 7.5 CVE-2021-36396 In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF… Moodle 3.9.8 / 3.10.5+ Fix from $1,9502023-03-06 HIGH 8.2 CVE-2023-23923 The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that prefer… Moodle 3.9.19 / 3.11.12+ Fix from $1,9502023-02-17 MEDIUM 6.1 CVE-2023-23921 The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacke… Moodle 3.9.19 / 3.11.12+ Fix from $1,6002023-02-17 MEDIUM 6.1 CVE-2023-23922 The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick th… Moodle 4.0.6+ Fix from $1,6002023-02-17 MEDIUM 6.1 CVE-2022-39183 Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors. Saml Authentication Mitigation only Fix from $1,6002023-01-12 CRITICAL 9.1 CVE-2022-45152 A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input … Moodle 3.9.18 / 3.11.11+ Fix from $2,3002022-11-25 MEDIUM 6.1 CVE-2022-45150 A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in p… Moodle 3.9.18 / 3.11.11+ Fix from $1,6002022-11-23 MEDIUM 5.4 CVE-2022-45149 A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF toke… Moodle 3.9.18 / 3.11.11+ Fix from $1,6002022-11-23