📦 Moodle

by Moodle

🔍 What is Moodle?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-33999

CRITICAL CVSS 9.8 May 31, 2024

This vulnerability in Moodle's MFA system allows attackers to bypass multi-factor authentication by manipulating the referrer URL. It affects Moodle installations with MFA enabled, potentially comprom...

CVE-2023-28333

CRITICAL CVSS 9.8 Mar 23, 2023

CVE-2023-28333 is a Mustache template injection vulnerability in Moodle's pix helper that could allow remote code execution if user input is improperly passed to the helper. The vulnerability affects ...

CVE-2021-36392

CRITICAL CVSS 9.8 Mar 6, 2023

CVE-2021-36392 is a critical SQL injection vulnerability in Moodle's user enrollment library that allows attackers to execute arbitrary SQL queries. This affects all Moodle instances with vulnerable v...

CVE-2021-36394

CRITICAL CVSS 9.8 Mar 6, 2023

CVE-2021-36394 is a critical remote code execution vulnerability in Moodle's Shibboleth authentication plugin. Attackers can execute arbitrary code on Moodle servers by exploiting session fixation iss...

CVE-2022-35649

CRITICAL CVSS 9.8 Jul 25, 2022

This critical Moodle vulnerability allows remote code execution through improper PostScript parsing in GhostScript. Attackers can exploit it to take complete control of vulnerable Moodle instances. Or...

CVE-2022-30599

CRITICAL CVSS 9.8 May 18, 2022

CVE-2022-30599 is a critical SQL injection vulnerability in Moodle's badges functionality that allows attackers to execute arbitrary SQL commands. This affects all Moodle instances with badges enabled...

CVE-2022-0332

CRITICAL CVSS 9.8 Jan 25, 2022

This SQL injection vulnerability in Moodle's H5P activity web service allows attackers to execute arbitrary SQL commands. It affects Moodle installations running versions 3.11 through 3.11.4. Attacker...

CVE-2021-3943

CRITICAL CVSS 9.8 Nov 22, 2021

This vulnerability allows remote attackers to execute arbitrary code on Moodle servers by exploiting improper input validation during backup file restoration. It affects Moodle installations running v...

CVE-2021-21809

CRITICAL CVSS 9.1 Jun 23, 2021

This vulnerability allows authenticated administrators in Moodle to execute arbitrary commands on the server through the legacy spellchecker plugin. Attackers with admin privileges can exploit special...

CVE-2026-26045

HIGH CVSS 7.2 Feb 21, 2026

This vulnerability in Moodle's backup restore functionality allows authenticated privileged users to upload specially crafted backup files that bypass validation, potentially leading to server-side co...

CVE-2025-67849

HIGH CVSS 7.3 Feb 3, 2026

This cross-site scripting vulnerability in Moodle allows attackers to inject malicious scripts through AI prompt responses. When users view compromised pages, attackers can steal session cookies or ma...

CVE-2025-67853

HIGH CVSS 7.5 Feb 3, 2026

This vulnerability in Moodle allows remote attackers to bypass rate limiting on confirmation email services, enabling brute-force attacks against user accounts. Attackers can more easily guess or enum...

CVE-2025-67850

HIGH CVSS 7.3 Feb 3, 2026

This Cross-Site Scripting (XSS) vulnerability in Moodle allows attackers to inject malicious JavaScript code into arithmetic expression fields in the formula editor. When other users view these compro...

CVE-2025-67848

HIGH CVSS 8.1 Feb 3, 2026

This authentication bypass vulnerability in Moodle allows suspended users to authenticate through the LTI Provider, enabling unauthorized access to the system. This affects Moodle instances using LTI ...

CVE-2025-67847

HIGH CVSS 8.8 Jan 23, 2026

This vulnerability allows attackers with access to Moodle's restore interface to execute arbitrary code on the server due to insufficient input validation. Successful exploitation could lead to comple...

CVE-2021-47857

HIGH CVSS 7.2 Jan 21, 2026

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in calendar event subtitles that allows attackers to inject malicious JavaScript. When users view a crafted calendar event, the m...

CVE-2025-62399

HIGH CVSS 7.5 Oct 23, 2025

CVE-2025-62399 allows attackers to perform brute-force attacks against Moodle's mobile and web service authentication endpoints due to insufficient rate limiting. This vulnerability could lead to unau...

CVE-2025-3638

HIGH CVSS 8.8 Apr 25, 2025

This CSRF vulnerability in Moodle's Brickfield tool allows attackers to trick authenticated users into unknowingly submitting analysis requests. Any Moodle instance with the Brickfield tool enabled is...

CVE-2025-3641

HIGH CVSS 8.8 Apr 25, 2025

A remote code execution vulnerability exists in Moodle's Dropbox repository feature, allowing authenticated teachers and managers to execute arbitrary code on the server. This affects Moodle installat...

CVE-2025-32044

HIGH CVSS 7.5 Apr 25, 2025

CVE-2025-32044 is an information disclosure vulnerability in Moodle where unauthenticated attackers can retrieve sensitive user data including names, contact information, and hashed passwords via stac...

CVE-2025-26533

HIGH CVSS 8.1 Feb 24, 2025

This SQL injection vulnerability in Moodle's course search module filter allows attackers to execute arbitrary SQL commands on the database. It affects Moodle installations with the vulnerable module ...

CVE-2025-26529

HIGH CVSS 8.3 Feb 24, 2025

This stored cross-site scripting (XSS) vulnerability in Moodle's site administration live log allows attackers to inject malicious scripts that execute when administrators view the log. It affects Moo...

CVE-2025-26530

HIGH CVSS 8.3 Feb 24, 2025

This reflected cross-site scripting (XSS) vulnerability in Moodle's question bank filter allows attackers to inject malicious scripts into web pages viewed by other users. When exploited, it could ena...

CVE-2024-45690

HIGH CVSS 7.5 Nov 20, 2024

This vulnerability in Moodle allows users to delete OAuth2-linked accounts without proper authorization checks. It affects Moodle instances with OAuth2 authentication enabled, potentially allowing use...

CVE-2024-43434

HIGH CVSS 8.1 Nov 7, 2024

This CSRF vulnerability in Moodle's Feedback module allows attackers to trick authenticated users into unknowingly sending bulk messages to non-respondents. Any Moodle instance with the Feedback modul...

CVE-2024-43438

HIGH CVSS 7.5 Nov 7, 2024

This vulnerability allows authenticated users with bulk messaging permissions to send messages to users who should not be visible in activity non-respondent reports. It affects Moodle installations wh...

CVE-2024-43425

HIGH CVSS 8.1 Nov 7, 2024

This vulnerability in Moodle allows authenticated users with question editing permissions to execute arbitrary code through calculated question types. It affects Moodle installations where users can a...

CVE-2024-43428

HIGH CVSS 7.7 Nov 7, 2024

This CVE addresses a cache poisoning vulnerability in Moodle that could allow attackers to manipulate locally cached data. The vulnerability affects Moodle installations where improper validation of l...

CVE-2024-38275

HIGH CVSS 7.5 Jun 18, 2024

The cURL wrapper in Moodle fails to strip HTTP authorization headers when following redirects, potentially exposing authentication credentials to third-party servers. This affects all Moodle instances...

CVE-2024-34007

HIGH CVSS 8.8 May 31, 2024

This CSRF vulnerability in MFA logout allows attackers to forcibly log out authenticated users by tricking them into clicking malicious links. It affects systems using the vulnerable MFA implementatio...

CVE-2024-34009

HIGH CVSS 7.5 May 31, 2024

This vulnerability allows attackers to bypass ReCAPTCHA protection on the login page of affected systems, potentially enabling brute-force attacks or unauthorized access attempts. It specifically affe...

CVE-2024-34001

HIGH CVSS 8.4 May 31, 2024

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Moodle's admin preset tool where actions lack anti-CSRF tokens. Attackers can trick authenticated administrators into performing...

CVE-2024-25978

HIGH CVSS 7.5 Feb 19, 2024

This vulnerability in Moodle's file picker unzip functionality allows attackers to cause denial of service by uploading specially crafted zip files that trigger excessive resource consumption. It affe...

CVE-2023-35133

HIGH CVSS 7.5 Jun 22, 2023

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Moodle's cURL blocked hosts list logic. The flaw allows attackers to bypass IP address restrictions by using 0.0.0.0, potential...

CVE-2021-36396

HIGH CVSS 7.5 Mar 6, 2023

This vulnerability in Moodle allows attackers to bypass cURL security restrictions through insufficient redirect handling, enabling blind Server-Side Request Forgery (SSRF). Attackers can make Moodle ...

CVE-2023-23923

HIGH CVSS 8.2 Feb 17, 2023

This Moodle vulnerability allows remote attackers to set the 'start page' preference for other users, bypassing intended access controls. Attackers can exploit this to access restricted functionality ...

CVE-2022-0983

HIGH CVSS 8.8 Mar 25, 2022

This CVE describes an SQL injection vulnerability in Badges code related to configuring criteria. It allows authenticated users with teacher or manager roles to execute arbitrary SQL commands. The vul...

CVE-2021-32476

HIGH CVSS 7.5 Mar 11, 2022

This vulnerability in Moodle's draft files area allows attackers to cause denial-of-service by bypassing user file upload limits. It affects Moodle installations from version 3.5 through 3.10.3, poten...

CVE-2021-32474

HIGH CVSS 7.2 Mar 11, 2022

This SQL injection vulnerability in Moodle allows attackers to execute arbitrary SQL commands via XML-RPC calls when MNet (Moodle Network) is enabled and configured. It requires either site administra...

CVE-2022-0335

HIGH CVSS 8.8 Jan 25, 2022

This Cross-Site Request Forgery (CSRF) vulnerability in Moodle allows attackers to trick authenticated users into unknowingly deleting badge alignments. Attackers can craft malicious requests that exe...

CVE-2021-43559

HIGH CVSS 8.8 Nov 22, 2021

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in Moodle's badge deletion functionality. Attackers can trick authenticated users into unknowingly deleting badges by crafting mali...

CVE-2026-26047

MEDIUM CVSS 6.5 Feb 21, 2026

This vulnerability allows authenticated Moodle users to craft malicious TeX formulas that consume excessive server resources when rendered, potentially causing denial-of-service conditions. It affects...

CVE-2025-67857

MEDIUM CVSS 4.3 Feb 3, 2026

This vulnerability in Moodle exposes user identifiers in URLs during anonymous assignment submissions, compromising intended anonymity. Attackers can view internal user IDs, leading to information dis...

CVE-2025-67851

MEDIUM CVSS 6.1 Feb 3, 2026

A formula injection vulnerability in Moodle allows remote attackers to embed malicious formulas in exported data. When users export this data and open it in spreadsheet applications like Excel or Libr...

CVE-2025-67855

MEDIUM CVSS 5.4 Feb 3, 2026

A reflected Cross-Site Scripting (XSS) vulnerability in Moodle's policy tool return URL allows attackers to inject malicious scripts through specially crafted links. This could lead to information dis...

CVE-2025-67856

MEDIUM CVSS 5.4 Feb 3, 2026

An authorization logic flaw in Moodle's badge awarding system allows users to obtain badges without proper role verification. This affects all Moodle instances with badge functionality enabled, potent...

CVE-2025-62397

MEDIUM CVSS 5.3 Oct 23, 2025

This vulnerability allows attackers to enumerate valid course IDs on a router by observing inconsistent responses to invalid IDs. This information disclosure could aid reconnaissance for further attac...

CVE-2025-62398

MEDIUM CVSS 5.4 Oct 23, 2025

This authentication bypass vulnerability allows attackers with valid credentials to circumvent multi-factor authentication under specific conditions, potentially gaining unauthorized access to user ac...

CVE-2025-62401

MEDIUM CVSS 5.4 Oct 23, 2025

A vulnerability in Moodle's timed assignment feature allows students to bypass time restrictions, potentially gaining extra time to complete assessments. This affects Moodle instances with timed assig...

CVE-2025-62393

MEDIUM CVSS 4.3 Oct 23, 2025

This vulnerability allows unauthorized users to view limited course information they shouldn't have access to due to insufficient permission checks in the course overview function. It affects Moodle i...

CVE-2025-62394

MEDIUM CVSS 4.3 Oct 23, 2025

Moodle fails to properly verify user enrolment status when sending quiz notifications, allowing suspended or inactive users to receive quiz-related messages. This leaks limited course information to u...

CVE-2025-62395

MEDIUM CVSS 4.3 Oct 23, 2025

This vulnerability allows users with lower-level permissions to access cohort information from the system context, potentially exposing restricted administrative data. It affects systems using the vul...

CVE-2025-62396

MEDIUM CVSS 5.3 Oct 23, 2025

An error-handling vulnerability in Moodle's router component (r.php) can expose internal directory listings when specific HTTP headers are misconfigured. This information disclosure affects Moodle ins...

CVE-2025-3643

MEDIUM CVSS 5.4 Apr 25, 2025

A reflected cross-site scripting (XSS) vulnerability exists in Moodle's policy tool where insufficient sanitization of return URLs allows attackers to inject malicious scripts. This affects all Moodle...

CVE-2025-3645

MEDIUM CVSS 4.3 Apr 25, 2025

This vulnerability in Moodle allows users to bypass authorization checks in a messaging web service, enabling them to view other users' names and online statuses without proper permissions. It affects...

CVE-2025-3636

MEDIUM CVSS 4.3 Apr 25, 2025

This vulnerability in Moodle allows unauthorized users to access RSS feeds due to insufficient permission checks. Any Moodle instance with RSS feeds enabled is affected, potentially exposing internal ...

CVE-2025-3627

MEDIUM CVSS 4.3 Apr 25, 2025

A Moodle vulnerability allows some users to access sensitive student information before identity verification via 2FA is completed. This affects Moodle instances with 2FA enabled where users can acces...

CVE-2025-26526

MEDIUM CVSS 6.5 Feb 24, 2025

This vulnerability allows users to bypass Separate Groups mode restrictions in Moodle's Feedback activities, enabling unauthorized viewing or deletion of responses. It affects Moodle installations usi...

CVE-2024-48899

MEDIUM CVSS 4.3 Nov 20, 2024

This vulnerability in Moodle allows authenticated users to view course badge lists for courses they shouldn't have access to. It's an improper access control issue affecting Moodle installations where...

CVE-2024-48897

MEDIUM CVSS 4.3 Nov 18, 2024

This CVE describes an improper authorization vulnerability in Moodle where users can edit or delete RSS feeds they shouldn't have permission to modify. It affects Moodle installations with RSS feed fu...

CVE-2024-48901

MEDIUM CVSS 4.3 Nov 18, 2024

This CVE describes an improper authorization vulnerability in Moodle where users can access report schedules without proper edit permissions. This affects Moodle instances where users have report view...

CVE-2024-43439

MEDIUM CVSS 5.4 Nov 11, 2024

This vulnerability in Moodle allows attackers to inject malicious scripts into H5P error messages, which are then reflected back to users. It affects Moodle instances with H5P content enabled, potenti...

CVE-2024-43432

MEDIUM CVSS 5.3 Nov 11, 2024

This vulnerability in Moodle's cURL wrapper could leak HTTP authorization credentials during redirects. When Moodle follows redirects, it strips HTTPAUTH and USERPWD headers but retains other authoriz...

CVE-2024-43435

MEDIUM CVSS 5.3 Nov 11, 2024

This vulnerability in Moodle allows users with course-level glossary restoration permissions to improperly restore glossaries into the global site glossary. This affects Moodle administrators and user...

CVE-2024-43429

MEDIUM CVSS 5.3 Nov 11, 2024

This vulnerability in Moodle allows unauthorized users to view hidden user profile fields through gradebook reports. Users without the 'view hidden user fields' capability can access sensitive informa...

CVE-2024-38277

MEDIUM CVSS 5.4 Jun 18, 2024

This vulnerability allows an attacker to use a QR login key interchangeably with an auto-login key, potentially bypassing authentication mechanisms. It affects systems using the vulnerable authenticat...

CVE-2024-38274

MEDIUM CVSS 6.1 Jun 18, 2024

This vulnerability allows attackers to inject malicious scripts into calendar event titles, which execute when users view the deletion prompt. This stored cross-site scripting (XSS) affects users of v...

CVE-2024-34002

MEDIUM CVSS 6.5 May 31, 2024

This vulnerability allows a Moodle user with specific permissions to execute local file includes in misconfigured shared hosting environments. Attackers could read sensitive files from the server if t...

CVE-2024-34004

MEDIUM CVSS 6.5 May 31, 2024

This vulnerability allows a Moodle user with wiki restore permissions and direct server access to execute local file includes in misconfigured shared hosting environments. It affects Moodle installati...

CVE-2024-34006

MEDIUM CVSS 4.3 May 31, 2024

This CVE describes a cross-site scripting (XSS) vulnerability in Moodle's site log report where HTML content in event descriptions isn't properly encoded. This allows attackers to inject malicious scr...

CVE-2024-33997

MEDIUM CVSS 6.1 May 31, 2024

This stored cross-site scripting (XSS) vulnerability in Moodle's equation editor allows attackers to inject malicious scripts when editing another user's equation. The scripts execute in victims' brow...

CVE-2025-67852

LOW CVSS 3.5 Feb 3, 2026

An open redirect vulnerability in Moodle's OAuth login flow allows attackers to redirect authenticated users to malicious websites. This affects all Moodle instances using OAuth authentication. Users ...