V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
Filters

All vulnerabilities

630 / 630
Vendor: moodle×Clear all
8.1
CVE-2024-43425DEB
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code executi…
2024-01-01Pre-auth
EPSS83.3%
pct 99
9.8
CVE-2021-36393DEB
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
2021-01-01Pre-auth
EPSS52.3%
pct 98
7.5
CVE-2022-35650DEB
The vulnerability was found in Moodle, occurs due to input validation error when importing less…
2022-01-01Pre-auth
EPSS49.1%
pct 98
9.8
CVE-2022-0332DEB
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in …
2022-01-01Pre-auth
EPSS44.9%
pct 98
4.6
CVE-2013-3630CVE
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs b…
2013-01-01
EPSS42.6%
pct 98
8.8
CVE-2018-1133DEB
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentional…
2018-01-01
EPSS32.2%
pct 98
9.1
CVE-2021-21809CVE
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.…
2021-01-01
EPSS24.2%
pct 97
4.3
CVE-2013-4341DEB
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.…
2013-01-01
EPSS21.9%
pct 97
8.8
CVE-2020-14321DEB
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign thems…
2020-01-01
EPSS16.4%
pct 96
6.5
CVE-2018-1042DEB
Moodle 3.x has Server Side Request Forgery in the filepicker.
2018-01-01
EPSS15.9%
pct 96
9.8
CVE-2017-2641DEB
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
2017-01-01Pre-auth
EPSS14.5%
pct 96
6.1
CVE-2019-3810DEB
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and…
2019-01-01Pre-auth
EPSS13.9%
pct 96
7.5
CVE-2006-0146DEB
The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including…
2006-01-01
EPSS12.9%
pct 95
7.5
CVE-2006-0147DEB
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4…
2006-01-01
EPSS12.8%
pct 95
4.3
CVE-2008-1502DEB
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWa…
2008-01-01
EPSS10.5%
pct 95
9.8
CVE-2021-36394DEB
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
2021-01-01Pre-auth
EPSS7.0%
pct 93
5.3
CVE-2023-30943DEB
The vulnerability was found Moodle which exists because the application allows a user to contro…
2023-01-01Pre-auth
EPSS6.6%
pct 92
9.8
CVE-2022-35649DEB
The vulnerability was found in Moodle, occurs due to improper input validation when parsing Pos…
2022-01-01Pre-auth
EPSS6.3%
pct 92
4.3
CVE-2009-1171DEB
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before…
2009-01-01
EPSS6.2%
pct 92
9.8
CVE-2022-30600DEB
A flaw was found in moodle where logic used to count failed login attempts could result in the …
2022-01-01Pre-auth
EPSS4.9%
pct 90
3.5
CVE-2014-3544DEB
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x be…
2014-01-01
EPSS4.7%
pct 90
4.3
CVE-2010-4207DEB
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 thr…
2010-01-01
EPSS4.5%
pct 90
4.3
CVE-2010-4208DEB
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 thr…
2010-01-01
EPSS4.4%
pct 90
8.8
CVE-2018-14630DEB
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos cou…
2018-01-01
EPSS4.4%
pct 90
6.8
CVE-2004-0725DEB
Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote …
2004-01-01
EPSS4.3%
pct 89
8.8
CVE-2016-9187CVE
Unrestricted file upload vulnerability in the double extension support in the "image" module in…
2016-01-01
EPSS4.0%
pct 89
4.3
CVE-2008-0123DEB
Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other ve…
2008-01-01
EPSS3.9%
pct 89
7.5
CVE-2007-6538DEB
SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for M…
2007-01-01
EPSS3.8%
pct 88
8.8
CVE-2016-9186CVE
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules …
2016-01-01
EPSS3.8%
pct 88
7.5
CVE-2014-3541DEB
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2…
2014-01-01
EPSS3.7%
pct 88
6.1
CVE-2020-25627DEB
The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk.…
2020-01-01Pre-auth
EPSS3.7%
pct 88
6.1
CVE-2022-35653DEB
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due …
2022-01-01Pre-auth
EPSS3.7%
pct 88
4.3
CVE-2011-4280DEB
Cross-site scripting (XSS) vulnerability in the Spike PHPCoverage (aka spikephpcoverage) librar…
2011-01-01
EPSS3.6%
pct 88
7.8
CVE-2007-1647DEB
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient acce…
2007-01-01
EPSS3.3%
pct 87
6.1
CVE-2019-14830DEB
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupp…
2019-01-01Pre-auth
EPSS3.3%
pct 86
3.5
CVE-2015-2269DEB
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle throu…
2015-01-01
EPSS3.3%
pct 86
2.6
CVE-2005-3649DEB
jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jum…
2005-01-01
EPSS3.1%
pct 85
8.8
CVE-2020-10738DEB
A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 …
2020-01-01
EPSS3.1%
pct 85
6.8
CVE-2014-0214DEB
login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x be…
2014-01-01
EPSS3.0%
pct 85
4.3
CVE-2007-3555DEB
Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers t…
2007-01-01
EPSS3.0%
pct 85
Select a vulnerability on the left to open the preview.