CVEs (625)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk. |
In Moodle, insufficient capability checks meant message deletions were not limited to the current user. |
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk. |
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service. |
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. |
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. |
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. |
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to ga...Show more |
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in blog search. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML...Show more |
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in some returnurl parameters. A remote attacker can trick the victim to follow a specially crafted link and execute a...Show more |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 25, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt...Show more |
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and s...Show more |
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafte...Show more |
A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a cour...Show more |
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Sep 30, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Sep 30, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A limited SQL injection risk was identified in the "browse list of users" site administration page. |
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Sep 30, 2022 N/A· v4 7.1 HIGH· v3 N/A· v2 Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load. |
It was possible for a student to view their quiz grade before it had been released, using a quiz web service. |