Vulnerabilities (CVE)

Filtered by vendor Moodle Subscribe
Total 526 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-4281 1 Moodle 1 Moodle 2023-11-07 6.8 MEDIUM N/A
Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitrary users for requests that mark the completion of (1) an activity or (2) a course.
CVE-2011-4280 2 Moodle, Nimish Pachapurkar 2 Moodle, Spike Phpcoverage 2023-11-07 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) library, as used in Moodle 2.0.x before 2.0.2 and other products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2011-4279 1 Moodle 1 Moodle 2023-11-07 5.0 MEDIUM N/A
Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attackers to obtain potentially sensitive information via vectors involving use of a search engine, as demonstrated by the search functionality of Google, Yahoo!, Wrensoft Zoom, MSN, Yandex, and AltaVista.
CVE-2011-4278 1 Moodle 1 Moodle 2023-11-07 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the tag autocomplete functionality in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2011-4133 1 Moodle 1 Moodle 2023-11-07 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified victims for requests that modify an RSS feed in an RSS block.
CVE-2004-2232 1 Moodle 1 Moodle 2023-11-07 7.5 HIGH N/A
SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.
CVE-2022-40316 2 Fedoraproject, Moodle 3 Extra Packages For Enterprise Linux, Fedora, Moodle 2023-08-08 N/A 4.3 MEDIUM
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
CVE-2022-0985 1 Moodle 1 Moodle 2023-07-21 4.0 MEDIUM 4.3 MEDIUM
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.
CVE-2022-40208 1 Moodle 1 Moodle 2023-03-30 N/A 4.3 MEDIUM
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.
CVE-2021-36403 1 Moodle 1 Moodle 2023-03-13 N/A 5.3 MEDIUM
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
CVE-2021-36402 1 Moodle 1 Moodle 2023-03-13 N/A 5.3 MEDIUM
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.
CVE-2021-36401 1 Moodle 1 Moodle 2023-03-13 N/A 4.8 MEDIUM
In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.
CVE-2021-36400 1 Moodle 1 Moodle 2023-03-13 N/A 5.3 MEDIUM
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
CVE-2021-36399 1 Moodle 1 Moodle 2023-03-13 N/A 5.4 MEDIUM
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
CVE-2021-36398 1 Moodle 1 Moodle 2023-03-13 N/A 5.4 MEDIUM
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
CVE-2021-36397 1 Moodle 1 Moodle 2023-03-13 N/A 5.3 MEDIUM
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
CVE-2021-36396 1 Moodle 1 Moodle 2023-03-13 N/A 7.5 HIGH
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
CVE-2021-36395 1 Moodle 1 Moodle 2023-03-13 N/A 7.5 HIGH
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.
CVE-2021-36394 1 Moodle 1 Moodle 2023-03-13 N/A 9.8 CRITICAL
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
CVE-2021-36393 1 Moodle 1 Moodle 2023-03-13 N/A 9.8 CRITICAL
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.