Vulnerabilities (CVE)

Filtered by vendor Moodle Subscribe
Total 631 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-38273 2 Fedoraproject, Moodle 2 Fedora, Moodle 2026-06-17 N/A 5.4 MEDIUM
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
CVE-2024-34312 1 Moodle 1 Virtual Programming Lab 2026-06-17 N/A 6.1 MEDIUM
Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.
CVE-2024-34009 1 Moodle 1 Moodle 2026-06-17 N/A 7.5 HIGH
Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.
CVE-2024-34008 1 Moodle 1 Moodle 2026-06-17 N/A 8.8 HIGH
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
CVE-2024-34007 1 Moodle 1 Moodle 2026-06-17 N/A 8.8 HIGH
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
CVE-2024-34006 1 Moodle 1 Moodle 2026-06-17 N/A 4.3 MEDIUM
The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.
CVE-2024-34005 1 Moodle 1 Moodle 2026-06-17 N/A 6.5 MEDIUM
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVE-2024-34004 1 Moodle 1 Moodle 2026-06-17 N/A 6.5 MEDIUM
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVE-2024-34003 1 Moodle 1 Moodle 2026-06-17 N/A 5.9 MEDIUM
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVE-2024-34002 1 Moodle 1 Moodle 2026-06-17 N/A 6.5 MEDIUM
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
CVE-2024-34001 1 Moodle 1 Moodle 2026-06-17 N/A 8.4 HIGH
Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
CVE-2024-34000 1 Moodle 1 Moodle 2026-06-17 N/A 4.3 MEDIUM
ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.
CVE-2024-33999 1 Moodle 1 Moodle 2026-06-17 N/A 9.8 CRITICAL
The referrer URL used by MFA required additional sanitizing, rather than being used directly.
CVE-2024-33998 1 Moodle 1 Moodle 2026-06-17 N/A 5.4 MEDIUM
Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacting with some features.
CVE-2024-33997 1 Moodle 1 Moodle 2026-06-17 N/A 6.1 MEDIUM
Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another user's equation.
CVE-2024-33996 1 Moodle 1 Moodle 2026-06-17 N/A 6.2 MEDIUM
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.
CVE-2024-29374 1 Moodle 1 Moodle 2026-06-17 N/A 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.
CVE-2024-28593 1 Moodle 1 Moodle 2026-06-17 N/A 5.4 MEDIUM
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be removed from standard Moodle."
CVE-2024-25983 2 Fedoraproject, Moodle 2 Fedora, Moodle 2026-06-17 N/A 3.5 LOW
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
CVE-2024-25982 2 Fedoraproject, Moodle 2 Fedora, Moodle 2026-06-17 N/A 4.3 MEDIUM
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.