moodle

629 tracked vulnerabilities.

CVE-2026-26047 MEDIUM
Moodle 4.5.0-4.5.8 and 5.1.0-beta-5.1.1 - Authenticated Denial of Service via TeX Formula Rendering
Feb 21, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-26046 HIGH
Moodle TeX Filter - Command Injection
Feb 21, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-26045 HIGH
Moodle 4.5.0-4.5.8 and 5.1.0-beta-5.1.1 - Authenticated Remote Code Execution via Backup Restore
Feb 21, 2026
CVSS 7.2
EPSS 0.00
CVE-2025-67857 MEDIUM
moodle < 4.1.21 and >= 0 < 4.1.22 - Unauthenticated User Identifier Exposure in Anonymous Assignment Submission URLs
Feb 03, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-67856 MEDIUM
Moodle < 4.1.22 - Incorrect Authorization in Badge Awarding Process
Feb 03, 2026
CVSS 5.4
EPSS 0.00
CVE-2025-67855 MEDIUM
Moodle < 4.1.22 - Reflected Cross-Site Scripting via Policy Tool Return URL
Feb 03, 2026
CVSS 5.4
EPSS 0.00
CVE-2025-67853 HIGH
Moodle < 4.1.22 - Improper Restriction of Excessive Authentication Attempts
Feb 03, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-67852 LOW
Moodle < 4.1.22 - Open Redirect via OAuth Login Flow
Feb 03, 2026
CVSS 3.5
EPSS 0.00
CVE-2025-67851 MEDIUM
moodle < 4.1.22 - Formula Injection via CSV Export
Feb 03, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-67850 HIGH
moodle < 4.1.22 - Stored Cross-Site Scripting in Formula Editor Arithmetic Expression Fields
Feb 03, 2026
CVSS 7.3
EPSS 0.00
CVE-2025-67849 HIGH
Moodle 4.5.0-4.5.7 and <4.1.22 - Stored Cross-Site Scripting via AI Prompt Response
Feb 03, 2026
CVSS 7.3
EPSS 0.00
CVE-2025-67848 HIGH
Moodle < 4.1.22 - Authentication Bypass via LTI Provider
Feb 03, 2026
CVSS 8.1
EPSS 0.00
CVE-2025-67847 HIGH
Moodle 4.1.0-4.1.21 and 5.1.0-beta - Authenticated Remote Code Execution via Restore Interface
Jan 23, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-62401 MEDIUM
Moodle 4.1.0-4.1.20 and 5.0.0-beta-5.0.2 - Improper Authorization in Timed Assignment Feature
Oct 23, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62400 MEDIUM
Moodle 4.1.0-4.1.20 and 5.0.0-beta-5.0.2 - Unauthorized Exposure of Hidden Group Names via Calendar Event Creation
Oct 23, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-62399 HIGH
Moodle 4.1.0-4.1.20 and 5.0.0-beta-5.0.2 - Brute-Force Attack via Authentication Endpoints
Oct 23, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-62398 MEDIUM
Moodle 4.4.0-4.4.10 and 5.0.0-beta-5.0.2 - Authenticated Multi-Factor Authentication Bypass
Oct 23, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62397 MEDIUM
moodle 5.0.0-5.0.3 - Information Disclosure via Invalid Course ID Error Response
Oct 23, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-62396 MEDIUM
Moodle 4.5.0-4.5.6 and 5.0.0-beta-5.0.2 - Directory Listing Exposure via Router Error Handling
Oct 23, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-62395 MEDIUM
moodle 4.1.0-4.1.20 - Improper Access Control in Cohort Search Web Service
Oct 23, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-62394 MEDIUM
Moodle 4.5.0-4.5.6 and 5.0.0-beta-5.0.2 - Incorrect Authorization in Quiz Notification
Oct 23, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-62393 MEDIUM
moodle 5.0.0-5.0.3 - Improper Access Control in Course Overview Output
Oct 23, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-53021 MEDIUM
Moodle 3.0.0-3.11.18 - Unauthenticated Session Fixation via sesskey Parameter
Jun 24, 2025
CVSS 4.2
EPSS 0.00
CVE-2025-34032 MEDIUM NUCLEI
Moodle Jmol Plugin < 6.1 - Reflected Cross-Site Scripting via jsmol.php Data Parameter
Jun 24, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-34031 HIGH NUCLEI
Moodle LMS Jmol plugin <6.1 - Path Traversal
Jun 24, 2025
CVSS 7.5
EPSS 0.18