Vulnerabilities > Moodle

DATE CVE VULNERABILITY TITLE RISK
2019-03-25 CVE-2019-3810 Cross-site Scripting vulnerability in Moodle
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions.
network
low complexity
moodle CWE-79
6.1
2019-03-25 CVE-2019-3809 Server-Side Request Forgery (SSRF) vulnerability in Moodle
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions.
network
low complexity
moodle CWE-918
critical
10.0
2019-03-25 CVE-2019-3808 Cross-site Scripting vulnerability in Moodle
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions.
network
low complexity
moodle CWE-79
5.4
2019-03-21 CVE-2019-6970 Server-Side Request Forgery (SSRF) vulnerability in Moodle
Moodle 3.5.x before 3.5.4 allows SSRF.
network
high complexity
moodle CWE-918
7.5
2018-11-26 CVE-2018-16854 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier.
network
low complexity
moodle CWE-352
8.8
2018-09-17 CVE-2018-14631 Cross-site Scripting vulnerability in Moodle
moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered.
network
low complexity
moodle CWE-79
6.1
2018-09-17 CVE-2018-14630 Code Injection vulnerability in Moodle
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution.
network
low complexity
moodle CWE-94
8.8
2018-07-10 CVE-2018-10891 Unspecified vulnerability in Moodle
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13.
network
low complexity
moodle
7.3
2018-07-10 CVE-2018-10890 Information Exposure vulnerability in Moodle
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13.
network
low complexity
moodle CWE-200
5.3
2018-07-10 CVE-2018-10889 Information Exposure Through Log Files vulnerability in Moodle
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7.
network
low complexity
moodle CWE-532
5.3