moodle Vulnerabilities and Affected Products
Vulnerabilities associated with moodle.
Products
Clear product- moodle55 vulnerabilities
- h5p2 vulnerabilities
- Jmol Plugin2 vulnerabilities
- LMS Jmol Plugin2 vulnerabilities
- LMS1 vulnerability
- Moodle LMS1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-47857MEDIUM | Moodle 3.10.3 - 'label' Persistent Cross Site ScriptingMoodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event. CWE-79Jan 21, 2026 | CVSS5.1v4.0 | EPSS0.309% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53021MEDIUM | Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameterA session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only af… CWE-384Jun 24, 2025 | CVSS4.2v3.1 | EPSS0.284% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Moodle: idor when deleting oauth2 linked accountsA flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts. | CVSS-v4.0 | EPSS0.353% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-43439MEDIUM | Moodle: reflected xss via h5p error messageA flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk. CWE-79Nov 11, 2024 | CVSS5.4v3.1 | EPSS0.357% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Moodle: can create global glossary without being adminA flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary. CWE-754Nov 11, 2024 | CVSS-v4.0 | EPSS0.336% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: matrix user/power level management not always working as expected with suspended usersA flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users. CWE-863Nov 11, 2024 | CVSS-v4.0 | EPSS0.318% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: authorization headers preserved between "emulated redirects"A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs. CWE-319Nov 11, 2024 | CVSS-v4.0 | EPSS0.323% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: lack of access control when using external methods for quiz overridesA flaw was found in moodle. External API access to Quiz can override contained insufficient access control. CWE-276Nov 11, 2024 | CVSS-v4.0 | EPSS0.318% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: user information visibility control issues in gradebook reportsA flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information. | CVSS-v4.0 | EPSS0.323% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: lfi vulnerability when restoring malformed block backupsA flaw was found in moodle. A local file may include risks when restoring block backups. CWE-22Nov 7, 2024 | CVSS-v4.0 | EPSS0.638% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: idor in feedback non-respondents report allows messaging arbitrary site usersA flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report. | CVSS-v4.0 | EPSS0.519% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: site administration sql injection via xmldb editorA SQL injection risk flaw was found in the XMLDB editor tool available to site administrators. CWE-89Nov 7, 2024 | CVSS-v4.0 | EPSS0.646% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: csrf risk in feedback non-respondents reportThe bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability. | CVSS-v4.0 | EPSS0.622% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: idor in badges allows deletion of arbitrary badgesA vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access. | CVSS-v4.0 | EPSS0.457% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: cache poisoning via injection into storageTo address a cache poisoning risk in Moodle, additional validation for local storage was required. | CVSS-v4.0 | EPSS0.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: arbitrary file read risk through pdftexA flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed. CWE-1287Nov 7, 2024 | CVSS-v4.0 | EPSS0.597% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Moodle: remote code execution via calculated question typesA flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions. | CVSS-v4.0 | EPSS83.2% | PoCs7 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX | |
CVE-2024-37674MEDIUM | Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity. CWE-79Jun 20, 2024 | CVSS5.5v3.1 | EPSS0.555% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keysA unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two. | CVSS-v4.0 | EPSS0.243% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
moodle: CSRF risks due to misuse of confirm_sesskeyIncorrect CSRF token checks resulted in multiple CSRF risks. CWE-352Jun 18, 2024 | CVSS-v4.0 | EPSS0.455% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
moodle: HTTP authorization header is preserved between "emulated redirects"The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs. | CVSS-v4.0 | EPSS0.445% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
moodle: stored XSS via calendar's event title when deleting the eventInsufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt. CWE-79Jun 18, 2024 | CVSS-v4.0 | EPSS0.374% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
moodle: BigBlueButton web service leaks meeting joining information to users who should not have accessInsufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access. CWE-284Jun 18, 2024 | CVSS-v4.0 | EPSS0.425% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
moodle: ReCAPTCHA can be bypassed on the login pageInsufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized. CWE-20May 31, 2024 | CVSS-v4.0 | EPSS0.419% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-34007HIGH | moodle: logout CSRF in admin/tool/mfa/auth.phpThe logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF. CWE-352May 31, 2024 | CVSS8.8v3.1 | EPSS0.314% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |