Vulnerabilities (CVE)

Filtered by vendor Moodle Subscribe
Total 589 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-2645 1 Moodle 1 Moodle 2025-04-20 4.3 MEDIUM 6.1 MEDIUM
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
CVE-2017-7531 1 Moodle 1 Moodle 2025-04-20 4.0 MEDIUM 4.3 MEDIUM
In Moodle 3.3, the course overview block reveals activities in hidden courses.
CVE-2016-8642 1 Moodle 1 Moodle 2025-04-20 5.0 MEDIUM 5.3 MEDIUM
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
CVE-2017-2641 1 Moodle 1 Moodle 2025-04-20 7.5 HIGH 9.8 CRITICAL
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
CVE-2017-7532 1 Moodle 1 Moodle 2025-04-20 4.0 MEDIUM 6.5 MEDIUM
In Moodle 3.x, course creators are able to change system default settings for courses.
CVE-2017-2578 1 Moodle 1 Moodle 2025-04-20 4.3 MEDIUM 6.1 MEDIUM
In Moodle 3.x, there is XSS in the assignment submission page.
CVE-2017-2643 1 Moodle 1 Moodle 2025-04-20 5.0 MEDIUM 5.3 MEDIUM
In Moodle 3.2.x, global search displays user names for unauthenticated users.
CVE-2017-7491 1 Moodle 1 Moodle 2025-04-20 4.3 MEDIUM 4.3 MEDIUM
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
CVE-2017-12157 1 Moodle 1 Moodle 2025-04-20 4.0 MEDIUM 4.3 MEDIUM
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
CVE-2015-5268 1 Moodle 1 Moodle 2025-04-12 4.0 MEDIUM 4.3 MEDIUM
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.
CVE-2015-5272 1 Moodle 1 Moodle 2025-04-12 4.0 MEDIUM 4.3 MEDIUM
The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."
CVE-2014-7838 1 Moodle 1 Moodle 2025-04-12 6.8 MEDIUM N/A
Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php, (2) mod/forum/forum.js, (3) mod/forum/index.php, or (4) mod/forum/lib.php.
CVE-2015-0216 1 Moodle 1 Moodle 2025-04-12 3.5 LOW N/A
access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback.
CVE-2015-3275 1 Moodle 1 Moodle 2025-04-12 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbitrary web script or HTML via a crafted organization name to (1) mod/scorm/player.php or (2) mod/scorm/prereqs.php.
CVE-2015-2269 1 Moodle 1 Moodle 2025-04-12 3.5 LOW N/A
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) alt or (2) title attribute in an IMG element.
CVE-2014-0217 1 Moodle 1 Moodle 2025-04-12 4.3 MEDIUM N/A
enrol/index.php in Moodle 2.6.x before 2.6.3 does not check for the moodle/course:viewhiddencourses capability before listing hidden courses, which allows remote attackers to obtain sensitive name and summary information about these courses by leveraging the guest role and visiting a crafted URL.
CVE-2014-0125 1 Moodle 1 Moodle 2025-04-12 5.8 MEDIUM N/A
repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, which allows remote attackers to bypass intended Alfresco Repository file restrictions by impersonating a file's owner.
CVE-2015-2271 1 Moodle 1 Moodle 2025-04-12 4.0 MEDIUM N/A
tag/user.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/tag:flag capability before proceeding with a flaginappropriate action, which allows remote authenticated users to bypass intended access restrictions via the "Flag as inappropriate" feature.
CVE-2014-7837 1 Moodle 1 Moodle 2025-04-12 5.5 MEDIUM N/A
mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.
CVE-2014-7836 1 Moodle 1 Moodle 2025-04-12 6.8 MEDIUM N/A
Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.