Skip to main content

Vendor archive

moodle CVEs

Beta · best-effort

631 CVEs tagged to vendor moodle23 Critical, 97 High, 463 Medium, 48 Low, 0 Unrated.

CVE-2023-23921

Published Feb 17, 2023

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to foll…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45151

Published Nov 23, 2022

The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker coul…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45150

Published Nov 23, 2022

A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can tr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45149

Published Nov 23, 2022

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2986

Published Oct 6, 2022

Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40314

Published Sep 30, 2022

A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-40695

Published Sep 29, 2022

It was possible for a student to view their quiz grade before it had been released, using a quiz web service.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40694

Published Sep 29, 2022

Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40693

Published Sep 29, 2022

An authentication bypass risk was identified in the external database authentication functionality, due to a type juggling vulnerability.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40692

Published Sep 29, 2022

Insufficient capability checks made it possible for teachers to download users outside of their courses.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40691

Published Sep 29, 2022

A session hijack risk was identified in the Shibboleth authentication plugin.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36568

Published Sep 13, 2022

In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1756

Published Aug 16, 2022

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1755

Published Aug 16, 2022

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14322

Published Aug 16, 2022

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14321

Published Aug 16, 2022

In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14320

Published Aug 16, 2022

In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1754

Published Aug 5, 2022

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1691

Published Aug 5, 2022

In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scripting.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 631 CVEsPage 7 of 26