moodle
629 tracked vulnerabilities.
CVE-2026-26047
MEDIUM
Moodle 4.5.0-4.5.8 and 5.1.0-beta-5.1.1 - Authenticated Denial of Service via TeX Formula Rendering
Feb 21, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-26046
HIGH
Moodle TeX Filter - Command Injection
Feb 21, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-26045
HIGH
Moodle 4.5.0-4.5.8 and 5.1.0-beta-5.1.1 - Authenticated Remote Code Execution via Backup Restore
Feb 21, 2026
CVSS 7.2
EPSS 0.00
CVE-2025-67857
MEDIUM
moodle < 4.1.21 and >= 0 < 4.1.22 - Unauthenticated User Identifier Exposure in Anonymous Assignment Submission URLs
Feb 03, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-67856
MEDIUM
Moodle < 4.1.22 - Incorrect Authorization in Badge Awarding Process
Feb 03, 2026
CVSS 5.4
EPSS 0.00
CVE-2025-67855
MEDIUM
Moodle < 4.1.22 - Reflected Cross-Site Scripting via Policy Tool Return URL
Feb 03, 2026
CVSS 5.4
EPSS 0.00
CVE-2025-67853
HIGH
Moodle < 4.1.22 - Improper Restriction of Excessive Authentication Attempts
Feb 03, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-67852
LOW
Moodle < 4.1.22 - Open Redirect via OAuth Login Flow
Feb 03, 2026
CVSS 3.5
EPSS 0.00
CVE-2025-67851
MEDIUM
moodle < 4.1.22 - Formula Injection via CSV Export
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-67850
HIGH
moodle < 4.1.22 - Stored Cross-Site Scripting in Formula Editor Arithmetic Expression Fields
Feb 03, 2026
CVSS 7.3
EPSS 0.00
CVE-2025-67849
HIGH
Moodle 4.5.0-4.5.7 and <4.1.22 - Stored Cross-Site Scripting via AI Prompt Response
Feb 03, 2026
CVSS 7.3
EPSS 0.00
CVE-2025-67848
HIGH
Moodle < 4.1.22 - Authentication Bypass via LTI Provider
Feb 03, 2026
CVSS 8.1
EPSS 0.00
CVE-2025-67847
HIGH
Moodle 4.1.0-4.1.21 and 5.1.0-beta - Authenticated Remote Code Execution via Restore Interface
Jan 23, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-62401
MEDIUM
Moodle 4.1.0-4.1.20 and 5.0.0-beta-5.0.2 - Improper Authorization in Timed Assignment Feature
Oct 23, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62400
MEDIUM
Moodle 4.1.0-4.1.20 and 5.0.0-beta-5.0.2 - Unauthorized Exposure of Hidden Group Names via Calendar Event Creation
Oct 23, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-62399
HIGH
Moodle 4.1.0-4.1.20 and 5.0.0-beta-5.0.2 - Brute-Force Attack via Authentication Endpoints
Oct 23, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-62398
MEDIUM
Moodle 4.4.0-4.4.10 and 5.0.0-beta-5.0.2 - Authenticated Multi-Factor Authentication Bypass
Oct 23, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62397
MEDIUM
moodle 5.0.0-5.0.3 - Information Disclosure via Invalid Course ID Error Response
Oct 23, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-62396
MEDIUM
Moodle 4.5.0-4.5.6 and 5.0.0-beta-5.0.2 - Directory Listing Exposure via Router Error Handling
Oct 23, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-62395
MEDIUM
moodle 4.1.0-4.1.20 - Improper Access Control in Cohort Search Web Service
Oct 23, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-62394
MEDIUM
Moodle 4.5.0-4.5.6 and 5.0.0-beta-5.0.2 - Incorrect Authorization in Quiz Notification
Oct 23, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-62393
MEDIUM
moodle 5.0.0-5.0.3 - Improper Access Control in Course Overview Output
Oct 23, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-53021
MEDIUM
Moodle 3.0.0-3.11.18 - Unauthenticated Session Fixation via sesskey Parameter
Jun 24, 2025
CVSS 4.2
EPSS 0.00
CVE-2025-34032
MEDIUM
NUCLEI
Moodle Jmol Plugin < 6.1 - Reflected Cross-Site Scripting via jsmol.php Data Parameter
Jun 24, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-34031
HIGH
NUCLEI
Moodle LMS Jmol plugin <6.1 - Path Traversal
Jun 24, 2025
CVSS 7.5
EPSS 0.18
Quick Filters