Moodle Security Vulnerabilities (CVEs)

Track 75 security vulnerabilities affecting Moodle products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

9 Critical
32 High
33 Medium
1 Low
🔔 Get Alerts for Moodle
CVE-2026-26047 6.5

This vulnerability allows authenticated Moodle users to craft malicious TeX formulas that consume excessive server resources when rendered, potentiall...

Feb 21, 2026
CVE-2026-26045 7.2

This vulnerability in Moodle's backup restore functionality allows authenticated privileged users to upload specially crafted backup files that bypass...

Feb 21, 2026
CVE-2025-67857 4.3

This vulnerability in Moodle exposes user identifiers in URLs during anonymous assignment submissions, compromising intended anonymity. Attackers can ...

Feb 3, 2026
CVE-2025-67849 7.3

This cross-site scripting vulnerability in Moodle allows attackers to inject malicious scripts through AI prompt responses. When users view compromise...

Feb 3, 2026
CVE-2025-67850 7.3

This Cross-Site Scripting (XSS) vulnerability in Moodle allows attackers to inject malicious JavaScript code into arithmetic expression fields in the ...

Feb 3, 2026
CVE-2025-67851 6.1

A formula injection vulnerability in Moodle allows remote attackers to embed malicious formulas in exported data. When users export this data and open...

Feb 3, 2026
CVE-2025-67852 3.5

An open redirect vulnerability in Moodle's OAuth login flow allows attackers to redirect authenticated users to malicious websites. This affects all M...

Feb 3, 2026
CVE-2025-67853 7.5

This vulnerability in Moodle allows remote attackers to bypass rate limiting on confirmation email services, enabling brute-force attacks against user...

Feb 3, 2026
CVE-2025-67855 5.4

A reflected Cross-Site Scripting (XSS) vulnerability in Moodle's policy tool return URL allows attackers to inject malicious scripts through specially...

Feb 3, 2026
CVE-2025-67856 5.4

An authorization logic flaw in Moodle's badge awarding system allows users to obtain badges without proper role verification. This affects all Moodle ...

Feb 3, 2026
CVE-2025-67848 8.1

This authentication bypass vulnerability in Moodle allows suspended users to authenticate through the LTI Provider, enabling unauthorized access to th...

Feb 3, 2026
CVE-2025-67847 8.8

This vulnerability allows attackers with access to Moodle's restore interface to execute arbitrary code on the server due to insufficient input valida...

Jan 23, 2026
CVE-2021-47857 7.2

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in calendar event subtitles that allows attackers to inject malicious JavaScrip...

Jan 21, 2026
CVE-2025-62397 5.3

This vulnerability allows attackers to enumerate valid course IDs on a router by observing inconsistent responses to invalid IDs. This information dis...

Oct 23, 2025
CVE-2025-62398 5.4

This authentication bypass vulnerability allows attackers with valid credentials to circumvent multi-factor authentication under specific conditions, ...

Oct 23, 2025
CVE-2025-62399 7.5

CVE-2025-62399 allows attackers to perform brute-force attacks against Moodle's mobile and web service authentication endpoints due to insufficient ra...

Oct 23, 2025
CVE-2025-62401 5.4

A vulnerability in Moodle's timed assignment feature allows students to bypass time restrictions, potentially gaining extra time to complete assessmen...

Oct 23, 2025
CVE-2025-62393 4.3

This vulnerability allows unauthorized users to view limited course information they shouldn't have access to due to insufficient permission checks in...

Oct 23, 2025
CVE-2025-62394 4.3

Moodle fails to properly verify user enrolment status when sending quiz notifications, allowing suspended or inactive users to receive quiz-related me...

Oct 23, 2025
CVE-2025-62395 4.3

This vulnerability allows users with lower-level permissions to access cohort information from the system context, potentially exposing restricted adm...

Oct 23, 2025
CVE-2025-62396 5.3

An error-handling vulnerability in Moodle's router component (r.php) can expose internal directory listings when specific HTTP headers are misconfigur...

Oct 23, 2025
CVE-2025-3643 5.4

A reflected cross-site scripting (XSS) vulnerability exists in Moodle's policy tool where insufficient sanitization of return URLs allows attackers to...

Apr 25, 2025
CVE-2025-3645 4.3

This vulnerability in Moodle allows users to bypass authorization checks in a messaging web service, enabling them to view other users' names and onli...

Apr 25, 2025
CVE-2025-3636 4.3

This vulnerability in Moodle allows unauthorized users to access RSS feeds due to insufficient permission checks. Any Moodle instance with RSS feeds e...

Apr 25, 2025
CVE-2025-3638 8.8

This CSRF vulnerability in Moodle's Brickfield tool allows attackers to trick authenticated users into unknowingly submitting analysis requests. Any M...

Apr 25, 2025
CVE-2025-3641 8.8

A remote code execution vulnerability exists in Moodle's Dropbox repository feature, allowing authenticated teachers and managers to execute arbitrary...

Apr 25, 2025
CVE-2025-32044 7.5

CVE-2025-32044 is an information disclosure vulnerability in Moodle where unauthenticated attackers can retrieve sensitive user data including names, ...

Apr 25, 2025
CVE-2025-3627 4.3

A Moodle vulnerability allows some users to access sensitive student information before identity verification via 2FA is completed. This affects Moodl...

Apr 25, 2025
CVE-2025-26533 8.1

This SQL injection vulnerability in Moodle's course search module filter allows attackers to execute arbitrary SQL commands on the database. It affect...

Feb 24, 2025
CVE-2025-26526 6.5

This vulnerability allows users to bypass Separate Groups mode restrictions in Moodle's Feedback activities, enabling unauthorized viewing or deletion...

Feb 24, 2025
CVE-2025-26529 8.3

This stored cross-site scripting (XSS) vulnerability in Moodle's site administration live log allows attackers to inject malicious scripts that execut...

Feb 24, 2025
CVE-2025-26530 8.3

This reflected cross-site scripting (XSS) vulnerability in Moodle's question bank filter allows attackers to inject malicious scripts into web pages v...

Feb 24, 2025
CVE-2024-45690 7.5

This vulnerability in Moodle allows users to delete OAuth2-linked accounts without proper authorization checks. It affects Moodle instances with OAuth...

Nov 20, 2024
CVE-2024-48899 4.3

This vulnerability in Moodle allows authenticated users to view course badge lists for courses they shouldn't have access to. It's an improper access ...

Nov 20, 2024
CVE-2024-48897 4.3

This CVE describes an improper authorization vulnerability in Moodle where users can edit or delete RSS feeds they shouldn't have permission to modify...

Nov 18, 2024
CVE-2024-48901 4.3

This CVE describes an improper authorization vulnerability in Moodle where users can access report schedules without proper edit permissions. This aff...

Nov 18, 2024
CVE-2024-43439 5.4

This vulnerability in Moodle allows attackers to inject malicious scripts into H5P error messages, which are then reflected back to users. It affects ...

Nov 11, 2024
CVE-2024-43432 5.3

This vulnerability in Moodle's cURL wrapper could leak HTTP authorization credentials during redirects. When Moodle follows redirects, it strips HTTPA...

Nov 11, 2024
CVE-2024-43435 5.3

This vulnerability in Moodle allows users with course-level glossary restoration permissions to improperly restore glossaries into the global site glo...

Nov 11, 2024
CVE-2024-43429 5.3

This vulnerability in Moodle allows unauthorized users to view hidden user profile fields through gradebook reports. Users without the 'view hidden us...

Nov 11, 2024
CVE-2024-43434 8.1

This CSRF vulnerability in Moodle's Feedback module allows attackers to trick authenticated users into unknowingly sending bulk messages to non-respon...

Nov 7, 2024
CVE-2024-43438 7.5

This vulnerability allows authenticated users with bulk messaging permissions to send messages to users who should not be visible in activity non-resp...

Nov 7, 2024
CVE-2024-43425 8.1

This vulnerability in Moodle allows authenticated users with question editing permissions to execute arbitrary code through calculated question types....

Nov 7, 2024
CVE-2024-43428 7.7

This CVE addresses a cache poisoning vulnerability in Moodle that could allow attackers to manipulate locally cached data. The vulnerability affects M...

Nov 7, 2024
CVE-2024-34312 6.1

Virtual Programming Lab for Moodle up to version 4.2.3 contains a cross-site scripting (XSS) vulnerability in the vplide.js component. This allows att...

Jun 24, 2024
CVE-2024-38277 5.4

This vulnerability allows an attacker to use a QR login key interchangeably with an auto-login key, potentially bypassing authentication mechanisms. I...

Jun 18, 2024
CVE-2024-38274 6.1

This vulnerability allows attackers to inject malicious scripts into calendar event titles, which execute when users view the deletion prompt. This st...

Jun 18, 2024
CVE-2024-38275 7.5

The cURL wrapper in Moodle fails to strip HTTP authorization headers when following redirects, potentially exposing authentication credentials to thir...

Jun 18, 2024
CVE-2024-34002 6.5

This vulnerability allows a Moodle user with specific permissions to execute local file includes in misconfigured shared hosting environments. Attacke...

May 31, 2024
CVE-2024-34004 6.5

This vulnerability allows a Moodle user with wiki restore permissions and direct server access to execute local file includes in misconfigured shared ...

May 31, 2024

Why Monitor Moodle Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 75+ known vulnerabilities affecting Moodle products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Moodle packages in under 60 seconds. No agents required - completely agentless scanning that works across Moodle deployments.

Free vulnerability database: Access detailed information about every Moodle CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Moodle CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Moodle CVEs Free