Filtered by vendor Moodle Subscriptions
Total 620 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-38276 2 Fedoraproject, Moodle 2 Fedora, Moodle 2025-03-26 8.8 High
Incorrect CSRF token checks resulted in multiple CSRF risks.
CVE-2024-34312 2 Moodle, Vpl 2 Virtual Programming Lab, Jail System 2025-03-25 6.1 Medium
Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.
CVE-2024-34008 1 Moodle 1 Moodle 2025-03-25 3.5 Low
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
CVE-2021-36399 1 Moodle 1 Moodle 2025-03-07 5.4 Medium
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
CVE-2021-36398 1 Moodle 1 Moodle 2025-03-07 5.4 Medium
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
CVE-2021-36397 1 Moodle 1 Moodle 2025-03-07 5.3 Medium
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
CVE-2021-36395 1 Moodle 1 Moodle 2025-03-07 7.5 High
In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.
CVE-2021-36403 1 Moodle 1 Moodle 2025-03-07 5.3 Medium
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
CVE-2021-36402 1 Moodle 1 Moodle 2025-03-07 5.3 Medium
In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.
CVE-2021-36401 1 Moodle 1 Moodle 2025-03-07 4.8 Medium
In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.
CVE-2021-36400 1 Moodle 1 Moodle 2025-03-07 5.3 Medium
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
CVE-2021-36394 1 Moodle 1 Moodle 2025-03-06 9.8 Critical
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
CVE-2021-36392 1 Moodle 1 Moodle 2025-03-06 9.8 Critical
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.
CVE-2021-36393 1 Moodle 1 Moodle 2025-03-06 9.8 Critical
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
CVE-2021-36396 1 Moodle 1 Moodle 2025-03-05 7.5 High
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
CVE-2023-28331 1 Moodle 1 Moodle 2025-02-26 6.1 Medium
Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
CVE-2022-40208 1 Moodle 1 Moodle 2025-02-20 4.3 Medium
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.
CVE-2024-25983 2 Fedoraproject, Moodle 2 Fedora, Moodle 2025-01-23 3.5 Low
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
CVE-2024-25978 2 Fedoraproject, Moodle 2 Fedora, Moodle 2025-01-23 7.5 High
Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.
CVE-2024-25979 2 Fedoraproject, Moodle 2 Fedora, Moodle 2025-01-23 5.3 Medium
The URL parameters accepted by forum search were not limited to the allowed parameters.