Loading HuntDB...

Moodle

3 Products 52 CVEs

CVE Severity Distribution (All Time)

Critical
0
High
8
Medium
13
Low
1

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 13 CVEs

Recent CVEs

View all
CVE-2024-45690 HIGH 9 months, 3 weeks ago

A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

CVE-2024-43439 UNKNOWN 9 months, 4 weeks ago

A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.

CVE-2024-43435 UNKNOWN 9 months, 4 weeks ago

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them in…

CVE-2024-43433 UNKNOWN 9 months, 4 weeks ago

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

CVE-2024-43432 UNKNOWN 9 months, 4 weeks ago

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original requ…

CVE-2024-43430 UNKNOWN 9 months, 4 weeks ago

A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.

CVE-2024-43429 UNKNOWN 9 months, 4 weeks ago

A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden us…

CVE-2024-43440 UNKNOWN 10 months ago

A flaw was found in moodle. A local file may include risks when restoring block backups.

CVE-2024-43438 UNKNOWN 10 months ago

A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users…

CVE-2024-43436 UNKNOWN 10 months ago

A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.