moodle
629 tracked vulnerabilities.
CVE-2011-4307
Moodle 2.0.x-2.0.5 and 2.1.x-2.1.2 - Cross-Site Scripting via Section Parameter
Jul 11, 2012
EPSS 0.00
CVE-2011-4306
Moodle < 1.9.14 - Authenticated Cross-Site Scripting in Course Section Editor
Jul 11, 2012
EPSS 0.00
CVE-2011-4305
Moodle 1.9.x - Authenticated Denial of Service via Message Refresh Zero Wait Time
Jul 11, 2012
EPSS 0.00
CVE-2011-4304
Moodle <2.0.5, <2.1.2 - Info Disclosure
Jul 11, 2012
EPSS 0.00
CVE-2011-4303
Moodle 2.0.x < 2.0.5 and 2.1.x < 2.1.2 - Unauthenticated Access Restriction Bypass via Hubs Feature
Jul 11, 2012
EPSS 0.00
CVE-2011-4302
Moodle 1.9.x < 1.9.14, 2.0.x < 2.0.5, 2.1.x < 2.1.2 - Certificate Validation Bypass via openssl_verify Return Value
Jul 11, 2012
EPSS 0.00
CVE-2011-4301
Moodle <1.9.14, <2.0.5, <2.1.2 - Code Injection
Jul 11, 2012
EPSS 0.00
CVE-2011-4300
Moodle <2.0.5-2.1.2 - Info Disclosure
Jul 11, 2012
EPSS 0.00
CVE-2011-4299
Moodle 2.0.0-2.0.4 - Authenticated Cross-Site Scripting via Wiki Comment
Jul 11, 2012
EPSS 0.00
CVE-2011-4298
Moodle 2.0.0-2.0.5 - Cross-Site Request Forgery in Wiki Module
Jul 11, 2012
EPSS 0.00
CVE-2011-4203
Moodle < 1.9.15 - CRLF Injection via Calendar URL Parameter
Dec 22, 2011
EPSS 0.00
CVE-2011-3757
Moodle 2.0.1 - Exposure of Sensitive Information via Direct Request to PHP Files
Sep 23, 2011
EPSS 0.00
CVE-2010-2231
Moodle < 1.8.13 and 1.9.x < 1.9.9 - Cross-Site Request Forgery via Quiz Attempt Deletion
Jun 28, 2010
EPSS 0.01
CVE-2010-2230
Moodle < 1.8.13 and 1.9.x < 1.9.9 - Authenticated Cross-Site Scripting via KSES Filter
Jun 28, 2010
EPSS 0.00
CVE-2010-2229
Moodle < 1.8.13 and 1.9.x < 1.9.9 - Cross-Site Scripting via Blog Index Parameters
Jun 28, 2010
EPSS 0.01
CVE-2010-2228
Moodle < 1.8.13 and 1.9.x < 1.9.9 - Cross-Site Scripting via Extended Characters in Username
Jun 28, 2010
EPSS 0.01
CVE-2010-1619
Moodle 1.8.0-1.8.11 - Cross-Site Scripting via Crafted HTML Entities
Apr 29, 2010
EPSS 0.00
CVE-2010-1618
phpCAS client library < 1.1.0 - Cross-Site Scripting via Crafted URL
Apr 29, 2010
EPSS 0.00
CVE-2010-1617
Moodle 1.8.x < 1.8.12 and 1.9.x < 1.9.8 - Authenticated Full Name Disclosure via Course Profile Page
Apr 29, 2010
EPSS 0.00
CVE-2010-1616
Moodle <1.9.8 - Privilege Escalation
Apr 29, 2010
EPSS 0.00
CVE-2010-1615
Moodle 1.8.0-1.8.11 - SQL Injection via Wiki Module or Form Select Groups
Apr 29, 2010
EPSS 0.00
CVE-2010-1614
Moodle 1.8.0-1.8.11 - Cross-Site Scripting via Login-As Feature or Global Search Forms
Apr 29, 2010
EPSS 0.00
CVE-2010-1613
Moodle 1.8.x-1.9.7 - Session Fixation via Default Session ID Regeneration Setting
Apr 29, 2010
EPSS 0.00
CVE-2009-4305
Moodle <1.8.11, <1.9.7 - SQL Injection
Dec 16, 2009
EPSS 0.01
CVE-2009-4304
Moodle <1.8.11-1.9.7 - Info Disclosure
Dec 16, 2009
EPSS 0.01
Quick Filters