Vulnerabilities
Vulnerable Software
Moodle:  >> Moodle  Security Vulnerabilities
Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-10-23
A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-10-23
An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.
CVSS Score
5.3
EPSS Score
0.0
Published
2025-10-23
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Score
4.2
EPSS Score
0.003
Published
2025-06-24
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.
CVSS Score
8.8
EPSS Score
0.014
Published
2025-04-25
A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.
CVSS Score
5.4
EPSS Score
0.002
Published
2025-04-25
A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.
CVSS Score
4.3
EPSS Score
0.003
Published
2025-04-25
A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.
CVSS Score
4.3
EPSS Score
0.003
Published
2025-04-25
A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.
CVSS Score
4.3
EPSS Score
0.003
Published
2025-04-25
A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.
CVSS Score
4.3
EPSS Score
0.004
Published
2025-04-25


Contact Us

Shodan ® - All rights reserved