Vulnerabilities > Moodle > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-11-14 | CVE-2012-1156 | Information Exposure Through Log Files vulnerability in multiple products Moodle before 2.2.2 has users' private files included in course backups | 7.5 |
2019-11-14 | CVE-2012-1155 | Information Exposure vulnerability in multiple products Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to | 7.5 |
2019-07-31 | CVE-2019-10186 | Cross-Site Request Forgery (CSRF) vulnerability in Moodle A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. | 8.8 |
2019-06-26 | CVE-2019-10154 | Unspecified vulnerability in Moodle A flaw was found in Moodle before versions 3.7, 3.6.4. | 7.5 |
2019-03-26 | CVE-2019-3849 | Improper Privilege Management vulnerability in Moodle A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. | 8.8 |
2019-03-21 | CVE-2019-6970 | Server-Side Request Forgery (SSRF) vulnerability in Moodle Moodle 3.5.x before 3.5.4 allows SSRF. | 7.5 |
2018-11-26 | CVE-2018-16854 | Cross-Site Request Forgery (CSRF) vulnerability in Moodle A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. | 8.8 |
2018-09-17 | CVE-2018-14630 | Code Injection vulnerability in Moodle moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. | 8.8 |
2018-07-10 | CVE-2018-10891 | Unspecified vulnerability in Moodle A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. | 7.3 |
2018-05-25 | CVE-2018-1137 | Improper Input Validation vulnerability in Moodle An issue was discovered in Moodle 3.x. | 8.1 |