Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2019-14884 A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error mess… Moodle 3.5.9 / 3.6.7+ Fix from $1,6002020-03-18 MEDIUM 5.3 CVE-2019-14883 A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were n… Moodle 3.6.7 / 3.7.3+ Fix from $1,6002020-03-18 MEDIUM 6.1 CVE-2019-14881 A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed. Moodle 3.7.2+ Fix from $1,6002020-03-18 MEDIUM 6.1 CVE-2019-14882 A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page. Moodle after 3.7.3 Fix from $1,6002020-03-18 MEDIUM 6.5 CVE-2020-1692 Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course. Moodle 3.7.2+ Fix from $1,6002020-02-17 MEDIUM 5.4 CVE-2019-18210 Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of… Moodle after 3.7.2 Fix from $1,6002020-02-11 MEDIUM 5.4 CVE-2019-14879 A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed… Moodle after 3.7.2 Fix from $1,6002020-01-07 HIGH 7.5 CVE-2012-1170 Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough Moodle 2.2.2+ Fix from $1,9502019-11-14 MEDIUM 5.3 CVE-2012-1169 Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are show… Moodle 2.2.2+ Fix from $1,6002019-11-14 HIGH 8.2 CVE-2012-1168 Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. Moodle 2.2.2+ Fix from $1,9502019-11-14 HIGH 7.5 CVE-2012-1155 Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from … Moodle 1.9.17 / 2.0.8+ Fix from $1,9502019-11-14 HIGH 7.5 CVE-2012-1156 Moodle before 2.2.2 has users' private files included in course backups Moodle 2.2.2+ Fix from $1,9502019-11-14 HIGH 8.8 CVE-2019-10186 A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool. Moodle 3.5.7 / 3.6.5+ Fix from $1,9502019-07-31 HIGH 7.5 CVE-2019-10154 A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations. Moodle 3.6.4+ Fix from $1,9502019-06-26 MEDIUM 6.1 CVE-2019-10133 A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricte… Moodle after 3.6.3 Fix from $1,6002019-06-26 HIGH 8.8 CVE-2019-3849 A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content… Moodle 3.4.8 / 3.5.5+ Fix from $1,9502019-03-26 MEDIUM 6.1 CVE-2019-3850 A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (… Moodle 3.1.17 / 3.4.8+ Fix from $1,6002019-03-26 CRITICAL 10.0 CVE-2019-3809 A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, w… Moodle after 3.1.15 Fix from $2,3002019-03-25 MEDIUM 6.1 CVE-2019-3810EPSS 14% A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did … Moodle after 3.6.1 Fix from $1,6002019-03-25 MEDIUM 5.4 CVE-2019-3808 A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' cap… Moodle after 3.5.3 Fix from $1,6002019-03-25 HIGH 7.5 CVE-2019-6970 Moodle 3.5.x before 3.5.4 allows SSRF. Moodle 3.5.4+ Fix from $1,9502019-03-21 HIGH 8.8 CVE-2018-16854 A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token t… Moodle 3.1.15 / 3.3.9+ Fix from $1,9502018-11-26 MEDIUM 6.1 CVE-2018-14631 moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigat… Moodle 3.3.8 / 3.4.5+ Fix from $1,6002018-09-17 HIGH 8.8 CVE-2018-14630 moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When imp… Moodle 3.1.14 / 3.3.8+ Fix from $1,9502018-09-17 HIGH 7.3 CVE-2018-10891 A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question previ… Moodle 3.1.13 / 3.3.7+ Fix from $1,9502018-07-10 MEDIUM 5.3 CVE-2018-10889 A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details o… Moodle 3.3.7 / 3.4.4+ Fix from $1,6002018-07-10 MEDIUM 5.3 CVE-2018-10890 A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidd… Moodle 3.1.13 / 3.3.7+ Fix from $1,6002018-07-10 HIGH 8.8 CVE-2018-1133EPSS 32% An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval… Moodle after 3.4.2 Fix from $1,9502018-05-25 HIGH 8.1 CVE-2018-1137 An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who a… Moodle after 3.4.2 Fix from $1,9502018-05-25 MEDIUM 6.5 CVE-2018-1134 An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle file by chan… Moodle after 3.4.2 Fix from $1,6002018-05-25