Vulnerability index

Browse CVEs

69 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Moodle MEDIUM 6.1
CVE-2021-47857

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious…

No fix yet
Fix from $1,600 2026-01-21
Moodle MEDIUM 5.5
CVE-2024-37674

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a ne…

No fix yet
Fix from $1,600 2024-06-20
Moodle MEDIUM 5.4
CVE-2024-28593

The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a per…

Mitigation only
Fix from $1,600 2024-03-22
Moodle MEDIUM 6.1
CVE-2024-29374

A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.

No fix yet
Fix from $1,600 2024-03-21
Moodle MEDIUM 5.4
CVE-2023-46858

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "S…

No fix yet
Fix from $1,600 2023-10-29
Moodle MEDIUM 5.4
CVE-2021-27131

Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" v…

No fix yet
Fix from $1,600 2023-05-16
Saml Authentication MEDIUM 6.1
CVE-2022-39183

Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.

Mitigation only
Fix from $1,600 2023-01-12
Moodle MEDIUM 5.4
CVE-2021-36568

In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type …

No fix yet
Fix from $1,600 2022-09-13
Moodle CRITICAL 9.1
CVE-2021-21809EPSS 24%

A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can le…

No fix yet
Fix from $2,300 2021-06-23
Moodle MEDIUM 5.4
CVE-2021-32244

Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.

No fix yet
Fix from $1,600 2021-06-16
Moodle MEDIUM 6.5
CVE-2018-1043

In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.

Mitigation only
Fix from $1,600 2018-01-22
Moodle MEDIUM 6.5
CVE-2016-3729

The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated…

Mitigation only
Fix from $1,600 2017-04-20
Moodle MEDIUM 5.3
CVE-2016-3731

Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussion…

Mitigation only
Fix from $1,600 2017-04-20
Moodle MEDIUM 5.4
CVE-2017-7298

In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.

No fix yet
Fix from $1,600 2017-03-29
Moodle HIGH 7.5
CVE-2016-7919

Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Admini…

No fix yet
Fix from $1,950 2016-10-28
Moodle MEDIUM 6.8
CVE-2015-5332

Atto in Moodle 2.8.x before 2.8.9 and 2.9.x before 2.9.3 allows remote attackers to cause a denial of service (disk consumption) by leveraging the gu…

Mitigation only
Fix from $1,600 2016-02-22
Moodle MEDIUM 6.1
CVE-2015-3274

Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x be…

Mitigation only
Fix from $1,600 2016-02-22
Moodle HIGH 7.4
CVE-2015-3272

Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.…

Mitigation only
Fix from $1,950 2016-02-22
Moodle MEDIUM 6.5
CVE-2013-1836

Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not properly manage privileges for WebDAV repositories…

Mitigation only
Fix from $1,600 2013-03-25
Moodle MEDIUM 5.5
CVE-2012-6106

calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remot…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 5.0
CVE-2012-6104

blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 5.0
CVE-2012-6105

blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed af…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 6.8
CVE-2012-6103

Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x befo…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 6.4
CVE-2012-6102

lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to rea…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 5.8
CVE-2012-6101

Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect us…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 6.5
CVE-2012-5479

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute…

Mitigation only
Fix from $1,600 2012-11-21
Moodle MEDIUM 6.4
CVE-2012-5480

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended rest…

Mitigation only
Fix from $1,600 2012-11-21
Moodle MEDIUM 6.5
CVE-2012-3395

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote auth…

Mitigation only
Fix from $1,600 2012-07-23
Moodle MEDIUM 5.5
CVE-2012-3392

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote a…

Mitigation only
Fix from $1,600 2012-07-23
Moodle MEDIUM 5.0
CVE-2012-3394

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an h…

Mitigation only
Fix from $1,600 2012-07-23