← Back

Moodle

moodle

Vendor: Moodle • 625 CVEs

CVEs (625)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Moodle before 2.2.2: Overview report allows users to see hidden courses
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
3Fedoraproject
MoodleRedhat
3Enterprise Linux
FedoraMoodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
3Fedoraproject
MoodleRedhat
3Enterprise Linux
FedoraMoodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moodle before 2.2.2 has users' private files included in course backups
4Debian
FedoraprojectMoodle+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
1Moodle
1Moodle
Jun 17, 2026
Jul 31, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.
1Moodle
1Moodle
Jun 17, 2026
Jul 31, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
1Moodle
1Moodle
Jun 17, 2026
Jul 31, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.
1Moodle
1Moodle
Jun 17, 2026
Jul 31, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
1Moodle
1Moodle
Jun 17, 2026
Jun 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
1Moodle
1Moodle
Jun 17, 2026
Jun 26, 2019
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
1Moodle
1Moodle
Jun 17, 2026
Jun 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
1Moodle
1Moodle
Jun 17, 2026
Mar 27, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScrip...Show more
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.Show less
1Moodle
1Moodle
Jun 17, 2026
Mar 26, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not taking context freezing into account when checking user capabilities
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Mar 26, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
1Moodle
1Moodle
Jun 17, 2026
Mar 26, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening wi...Show more
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.Show less
1Moodle
1Moodle
Jun 17, 2026
Mar 26, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
1Moodle
1Moodle
Jun 17, 2026
Mar 26, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users...Show more
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)Show less