Total
535 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-38276 | 2 Fedoraproject, Moodle | 2 Fedora, Moodle | 2025-03-26 | N/A | 8.8 HIGH |
Incorrect CSRF token checks resulted in multiple CSRF risks. | |||||
CVE-2024-34008 | 1 Moodle | 1 Moodle | 2025-03-25 | N/A | 8.8 HIGH |
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk. | |||||
CVE-2021-36399 | 1 Moodle | 1 Moodle | 2025-03-07 | N/A | 5.4 MEDIUM |
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk. | |||||
CVE-2021-36398 | 1 Moodle | 1 Moodle | 2025-03-07 | N/A | 5.4 MEDIUM |
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk. | |||||
CVE-2021-36397 | 1 Moodle | 1 Moodle | 2025-03-07 | N/A | 5.3 MEDIUM |
In Moodle, insufficient capability checks meant message deletions were not limited to the current user. | |||||
CVE-2021-36395 | 1 Moodle | 1 Moodle | 2025-03-07 | N/A | 7.5 HIGH |
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service. | |||||
CVE-2021-36403 | 1 Moodle | 1 Moodle | 2025-03-07 | N/A | 5.3 MEDIUM |
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk. | |||||
CVE-2021-36402 | 1 Moodle | 1 Moodle | 2025-03-07 | N/A | 5.3 MEDIUM |
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk. | |||||
CVE-2021-36401 | 1 Moodle | 1 Moodle | 2025-03-07 | N/A | 4.8 MEDIUM |
In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk. | |||||
CVE-2021-36400 | 1 Moodle | 1 Moodle | 2025-03-07 | N/A | 5.3 MEDIUM |
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. | |||||
CVE-2021-36394 | 1 Moodle | 1 Moodle | 2025-03-06 | N/A | 9.8 CRITICAL |
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. | |||||
CVE-2021-36396 | 1 Moodle | 1 Moodle | 2025-03-05 | N/A | 7.5 HIGH |
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk. | |||||
CVE-2023-28331 | 1 Moodle | 1 Moodle | 2025-02-25 | N/A | 6.1 MEDIUM |
Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk. | |||||
CVE-2022-40208 | 1 Moodle | 1 Moodle | 2025-02-20 | N/A | 4.3 MEDIUM |
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt. | |||||
CVE-2024-25983 | 2 Fedoraproject, Moodle | 2 Fedora, Moodle | 2025-01-23 | N/A | 3.5 LOW |
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page). | |||||
CVE-2024-25978 | 2 Fedoraproject, Moodle | 2 Fedora, Moodle | 2025-01-23 | N/A | 7.5 HIGH |
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality. | |||||
CVE-2024-25979 | 2 Fedoraproject, Moodle | 2 Fedora, Moodle | 2025-01-23 | N/A | 5.3 MEDIUM |
The URL parameters accepted by forum search were not limited to the allowed parameters. | |||||
CVE-2024-25980 | 2 Fedoraproject, Moodle | 2 Fedora, Moodle | 2025-01-23 | N/A | 4.3 MEDIUM |
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers. | |||||
CVE-2024-25981 | 2 Fedoraproject, Moodle | 2 Fedora, Moodle | 2025-01-23 | N/A | 4.3 MEDIUM |
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers. | |||||
CVE-2024-25982 | 2 Fedoraproject, Moodle | 2 Fedora, Moodle | 2025-01-23 | N/A | 4.3 MEDIUM |
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. |