Where
AND
-Infinity
0

Moodle Moodle LMSMoodle LMS 4.0 Cross-Site Scripting via course search.php

Risk 38
Severity
5.1
First published (updated )

Moodle MoodleMoodle: moodle: uncontrolled resource consumption in tex formula editor leading to denial of service

Risk 27
Severity
6.5
EPSS
0.07%
First published (updated )

Moodle MoodleA Denial-of-Service vulnerability exists in Moodle’s TeX formula editor due to missing execution tim…

Risk 19
Severity
4
First published (updated )

Moodle MoodleMoodle: moodle: data exposure of user identifiers in urls

Risk 27
Severity
5.3
First published (updated )

composer/moodle/moodleMooodle: mooodle: information disclosure and script execution via reflected cross-site scripting

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Moodle MoodleMoodle: moodle: open redirect vulnerability in oauth login flow allows redirection to malicious sites.

Risk 38
Severity
6.1
First published (updated )

Moodle MoodleMoodle: idor when accessing the cohorts report

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )

Moodle MoodleMoodle: idor in messaging web service allows access to some user details

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )

Moodle MoodleMoodle: ajax section delete does not respect course_can_delete_section()

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )

Moodle MoodleMoodle: reflected xss risk in policy tool

Risk 25
Severity
5.4
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Moodle MoodleMoodle: idor in web service allows users enrolled in a course to access some details of other users

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )

Moodle MoodleMoodle: idor in moodle rss block allows unauthorized access to rss feeds

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )

Moodle MoodleMoodle: moodle assignment submission search leaks anonymous student identities

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )

Moodle MoodleMoodle: partial data exposure in moodle before completing multi-factor authentication

Risk 16
Severity
4.3
EPSS
0.04%
First published (updated )

Moodle MoodleMoodle: hidden grades shown to users without permission on some grade reports

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/moodle/moodleTeachers can evade trusttext config when restoring glossary entries

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )

composer/moodle/moodleIDOR in badges allows disabling of arbitrary badges

Risk 19
Severity
5.3
EPSS
0.03%
First published (updated )

composer/moodle/moodleStored XSS in ddimageortext question type

Risk 27
Severity
6.1
EPSS
0.03%
First published (updated )

composer/moodle/moodleNon-searchable tags can still be discovered on the tag search page and in the tags block

Risk 19
Severity
5.3
EPSS
0.04%
First published (updated )

composer/moodle/moodleFeedback response viewing and deletions did not respect Separate Groups mode

Risk 28
Severity
6.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Moodle moodleXSS

Risk 40
Severity
5.5
First published (updated )

composer/moodle/moodleMsa-24-0003: h5p attempts report did not respect activity group settings

Risk 20
Severity
5.3
EPSS
0.04%
First published (updated )

composer/moodle/moodleMsa-24-0002: forum search accepted random parameters in its url

Risk 20
Severity
5.3
EPSS
0.04%
First published (updated )

composer/moodle/moodleMsa-24-0006: idor on dashboard comments block

Risk 20
Severity
5.3
EPSS
0.04%
First published (updated )

composer/moodle/moodleMsa-24-0004: forum export did not respect activity group settings

Risk 20
Severity
5.3
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/moodle/moodleInadequate access control vulnerability in Moodle

Risk 40
Severity
6.5
First published (updated )

redhat/moodleMoodle: minor sql injection risk on mnet sso access control page

Risk 48
Severity
6.3
First published (updated )

redhat/moodleMoodle: xss risk on groups page

Risk 40
Severity
6.1
First published (updated )

Moodle moodleMoodle: course participation report shows roles the user should not see

Risk 24
Severity
4.3
First published (updated )

Moodle moodleMoodle: teacher can access names of users they do not have permission to access

Risk 24
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203