Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2022-45151
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user pr…
Moodle
3.11.11 / 4.0.5+
HIGH 8.8
CVE-2022-2986
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
Moodle
3.11.9 / 4.0.3+
CRITICAL 9.8
CVE-2022-40314
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
Moodle
3.9.17 / 3.11.10+
CRITICAL 9.8
CVE-2022-40315
A limited SQL injection risk was identified in the "browse list of users" site administration page.
Moodle
3.9.17 / 3.11.10+
HIGH 7.1
CVE-2022-40313
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
Moodle
3.9.17 / 3.11.10+
MEDIUM 6.5
CVE-2021-40693
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.
Moodle
3.9.10 / 3.10.7+
MEDIUM 5.4
CVE-2021-36568
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type …
Moodle
No fix yet
HIGH 8.8
CVE-2020-14321EPSS 16%
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
Moodle
3.5.13 / 3.7.7+
HIGH 7.5
CVE-2020-14322
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of ser…
Moodle
3.5.13 / 3.7.7+
HIGH 7.2
CVE-2020-1756
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.
Moodle
3.5.11 / 3.6.9+
MEDIUM 6.1
CVE-2020-14320
In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.
Moodle
3.7.7 / 3.8.4+
MEDIUM 5.3
CVE-2020-1755
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
Moodle
3.5.11 / 3.6.9+
MEDIUM 5.4
CVE-2020-1691
In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.
Moodle
Patch available
CRITICAL 9.8
CVE-2022-35649EPSS 8%
The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results i…
Moodle
3.9.15 / 3.11.8+
HIGH 7.5
CVE-2022-35650EPSS 49%
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in…
Moodle
3.9.15 / 3.11.8+
MEDIUM 6.1
CVE-2022-35651
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track detai…
Moodle
3.9.15 / 3.11.8+
MEDIUM 6.1
CVE-2022-35652
An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can cre…
Moodle
3.9.15 / 3.11.8+
MEDIUM 6.1
CVE-2022-35653
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in …
Moodle
3.9.15 / 3.11.8+
CRITICAL 9.8
CVE-2022-30599
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
Moodle
3.9.14 / 3.10.11+
CRITICAL 9.8
CVE-2022-30600EPSS 5%
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
Moodle
3.9.14 / 3.10.11+
MEDIUM 5.3
CVE-2022-30597
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
Moodle
3.9.14 / 3.10.11+
MEDIUM 5.4
CVE-2022-30596
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored …
Moodle
3.9.14 / 3.10.11+
HIGH 8.8
CVE-2022-0983
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and m…
Moodle
3.9.13 / 3.10.10+
MEDIUM 6.1
CVE-2021-32478
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 t…
Moodle
3.8.9 / 3.9.7+
HIGH 7.5
CVE-2021-32476
A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.…
Moodle
3.5.18 / 3.8.9+
MEDIUM 5.4
CVE-2021-32475
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8…
Moodle
3.5.18 / 3.8.9+
HIGH 7.2
CVE-2021-32474
An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required si…
Moodle
3.5.18 / 3.8.9+
MEDIUM 5.3
CVE-2021-32473
It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.…
Moodle
3.5.18 / 3.8.9+
CRITICAL 9.8
CVE-2022-0332EPSS 45%
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching …
Moodle
3.11.5+
HIGH 8.8
CVE-2022-0335
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" f…
Moodle
3.9.12 / 3.10.9+