Filtered by vendor Moodle
Subscriptions
Filtered by product Moodle
Subscriptions
Total
634 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2017-7491 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting. | ||||
| CVE-2016-3734 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read. | ||||
| CVE-2016-7038 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed. | ||||
| CVE-2017-7489 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link. | ||||
| CVE-2017-2576 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums. | ||||
| CVE-2017-2644 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 3.x, XSS can occur via evidence of prior learning. | ||||
| CVE-2016-5012 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 3.x, glossary search displays entries without checking user permissions to view them. | ||||
| CVE-2017-7531 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 3.3, the course overview block reveals activities in hidden courses. | ||||
| CVE-2016-8642 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 2.x and 3.x, the question engine allows access to files that should not be available. | ||||
| CVE-2017-2645 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 3.x, XSS can occur via attachments to evidence of prior learning. | ||||
| CVE-2017-2643 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 3.2.x, global search displays user names for unauthenticated users. | ||||
| CVE-2017-12157 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access. | ||||
| CVE-2016-8643 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services. | ||||
| CVE-2016-5014 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
| In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course. | ||||
| CVE-2015-0211 | 1 Moodle | 1 Moodle | 2025-04-12 | N/A |
| mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities before proceeding with registered-tool list searches, which allows remote authenticated users to obtain sensitive information via requests to the LTI Ajax service. | ||||
| CVE-2015-0218 | 1 Moodle | 1 Moodle | 2025-04-12 | N/A |
| Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout. | ||||
| CVE-2013-7341 | 2 Flowplayer, Moodle | 2 Flowplayer Flash, Moodle | 2025-04-12 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342. | ||||
| CVE-2015-0217 | 1 Moodle | 1 Moodle | 2025-04-12 | N/A |
| filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to cause a denial of service (CPU consumption or partial outage) via a crafted string that is matched against an improper regular expression. | ||||
| CVE-2014-3553 | 1 Moodle | 1 Moodle | 2025-04-12 | N/A |
| mod/forum/classes/post_form.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce the moodle/site:accessallgroups capability requirement before proceeding with a post to all groups, which allows remote authenticated users to bypass intended access restrictions by leveraging two or more group memberships. | ||||
| CVE-2015-0216 | 1 Moodle | 1 Moodle | 2025-04-12 | N/A |
| access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted essay feedback. | ||||