Vulnerabilities > Moodle > Low

DATE CVE VULNERABILITY TITLE RISK
2023-11-09 CVE-2023-5543 When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity.
local
low complexity
moodle fedoraproject
3.3
2023-11-09 CVE-2023-5551 Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
local
low complexity
moodle fedoraproject
3.3
2022-03-11 CVE-2021-32475 Cross-site Scripting vulnerability in Moodle
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
network
moodle CWE-79
3.5
2022-01-25 CVE-2022-0333 Incorrect Authorization vulnerability in Moodle
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions.
network
low complexity
moodle CWE-863
3.8
2021-06-16 CVE-2021-32244 Cross-site Scripting vulnerability in Moodle 3.10.3
Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.
network
moodle CWE-79
3.5
2021-01-28 CVE-2021-20186 Cross-site Scripting vulnerability in Moodle
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.
network
high complexity
moodle CWE-79
2.1
2020-02-11 CVE-2019-18210 Cross-site Scripting vulnerability in Moodle
Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter.
network
moodle CWE-79
3.5
2018-01-22 CVE-2018-1045 Cross-site Scripting vulnerability in Moodle
In Moodle 3.x, there is XSS via a calendar event name.
network
moodle CWE-79
3.5
2017-03-29 CVE-2017-7298 Cross-site Scripting vulnerability in Moodle 3.2.2
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.
network
moodle CWE-79
3.5
2016-02-22 CVE-2015-5269 Cross-site Scripting vulnerability in Moodle
Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.
network
moodle CWE-79
3.5