← Back

Moodle

moodle

Vendor: Moodle • 625 CVEs

CVEs (625)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moodle
1Moodle
Nov 21, 2024
Jan 22, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Moodle 3.x has Server Side Request Forgery in the filepicker.
1Moodle
1Moodle
May 13, 2026
Nov 20, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility....Show more
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.Show less
1Moodle
1Moodle
May 13, 2026
Sep 18, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
1Moodle
1Moodle
May 13, 2026
Sep 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
1Moodle
1Moodle
May 13, 2026
Jul 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Moodle 3.x, course creators are able to change system default settings for courses.
1Moodle
1Moodle
May 13, 2026
Jul 17, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Moodle 3.3, the course overview block reveals activities in hidden courses.
1Moodle
1Moodle
May 13, 2026
Jul 17, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Moodle 3.x has user fullname disclosure on the user preferences page.
1Moodle
1Moodle
May 13, 2026
May 15, 2017
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
1Moodle
1Moodle
May 13, 2026
May 15, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
1Moodle
1Moodle
May 13, 2026
May 15, 2017
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.
1Moodle
1Moodle
May 13, 2026
Apr 20, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of...Show more
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.Show less
1Moodle
1Moodle
May 13, 2026
Apr 20, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.
1Moodle
1Moodle
May 13, 2026
Apr 20, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users.
1Moodle
1Moodle
May 13, 2026
Apr 20, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.
1Moodle
1Moodle
May 13, 2026
Apr 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.
1Moodle
1Moodle
May 13, 2026
Mar 29, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.
1Moodle
1Moodle
May 13, 2026
Mar 26, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
1Moodle
1Moodle
May 13, 2026
Mar 26, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Moodle 3.x, XSS can occur via evidence of prior learning.
1Moodle
1Moodle
May 13, 2026
Mar 26, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Moodle 3.2.x, global search displays user names for unauthenticated users.
1Moodle
1Moodle
May 13, 2026
Mar 26, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.