Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2022-45151 The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user pr… Moodle 3.11.11 / 4.0.5+ Fix from $1,6002022-11-23 HIGH 8.8 CVE-2022-2986 Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk. Moodle 3.11.9 / 4.0.3+ Fix from $1,9502022-10-06 CRITICAL 9.8 CVE-2022-40314 A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified. Moodle 3.9.17 / 3.11.10+ Fix from $2,3002022-09-30 CRITICAL 9.8 CVE-2022-40315 A limited SQL injection risk was identified in the "browse list of users" site administration page. Moodle 3.9.17 / 3.11.10+ Fix from $2,3002022-09-30 HIGH 7.1 CVE-2022-40313 Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load. Moodle 3.9.17 / 3.11.10+ Fix from $1,9502022-09-30 MEDIUM 6.5 CVE-2021-40693 An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability. Moodle 3.9.10 / 3.10.7+ Fix from $1,6002022-09-29 MEDIUM 5.4 CVE-2021-36568 In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type … Moodle No fix yet Fix from $1,6002022-09-13 HIGH 8.8 CVE-2020-14321EPSS 16% In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course. Moodle 3.5.13 / 3.7.7+ Fix from $1,9502022-08-16 HIGH 7.5 CVE-2020-14322 In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of ser… Moodle 3.5.13 / 3.7.7+ Fix from $1,9502022-08-16 HIGH 7.2 CVE-2020-1756 In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool. Moodle 3.5.11 / 3.6.9+ Fix from $1,9502022-08-16 MEDIUM 6.1 CVE-2020-14320 In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk. Moodle 3.7.7 / 3.8.4+ Fix from $1,6002022-08-16 MEDIUM 5.3 CVE-2020-1755 In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks. Moodle 3.5.11 / 3.6.9+ Fix from $1,6002022-08-16 MEDIUM 5.4 CVE-2020-1691 In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting. Moodle Patch available Fix from $1,6002022-08-05 CRITICAL 9.8 CVE-2022-35649EPSS 8% The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results i… Moodle 3.9.15 / 3.11.8+ Fix from $2,3002022-07-25 HIGH 7.5 CVE-2022-35650EPSS 49% The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in… Moodle 3.9.15 / 3.11.8+ Fix from $1,9502022-07-25 MEDIUM 6.1 CVE-2022-35651 A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track detai… Moodle 3.9.15 / 3.11.8+ Fix from $1,6002022-07-25 MEDIUM 6.1 CVE-2022-35652 An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can cre… Moodle 3.9.15 / 3.11.8+ Fix from $1,6002022-07-25 MEDIUM 6.1 CVE-2022-35653 A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in … Moodle 3.9.15 / 3.11.8+ Fix from $1,6002022-07-25 CRITICAL 9.8 CVE-2022-30599 A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria. Moodle 3.9.14 / 3.10.11+ Fix from $2,3002022-05-18 CRITICAL 9.8 CVE-2022-30600EPSS 5% A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed. Moodle 3.9.14 / 3.10.11+ Fix from $2,3002022-05-18 MEDIUM 5.3 CVE-2022-30597 A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field. Moodle 3.9.14 / 3.10.11+ Fix from $1,6002022-05-18 MEDIUM 5.4 CVE-2022-30596 A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored … Moodle 3.9.14 / 3.10.11+ Fix from $1,6002022-05-18 HIGH 8.8 CVE-2022-0983 An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and m… Moodle 3.9.13 / 3.10.10+ Fix from $1,9502022-03-25 MEDIUM 6.1 CVE-2021-32478 The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 t… Moodle 3.8.9 / 3.9.7+ Fix from $1,6002022-03-11 HIGH 7.5 CVE-2021-32476 A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.… Moodle 3.5.18 / 3.8.9+ Fix from $1,9502022-03-11 MEDIUM 5.4 CVE-2021-32475 ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8… Moodle 3.5.18 / 3.8.9+ Fix from $1,6002022-03-11 HIGH 7.2 CVE-2021-32474 An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required si… Moodle 3.5.18 / 3.8.9+ Fix from $1,9502022-03-11 MEDIUM 5.3 CVE-2021-32473 It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.… Moodle 3.5.18 / 3.8.9+ Fix from $1,6002022-03-11 CRITICAL 9.8 CVE-2022-0332EPSS 45% A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching … Moodle 3.11.5+ Fix from $2,3002022-01-25 HIGH 8.8 CVE-2022-0335 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" f… Moodle 3.9.12 / 3.10.9+ Fix from $1,9502022-01-25