Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Moodle — Vulnerabilities & Security Advisories 25

Browse all 25 CVE security advisories affecting Moodle. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Moodle is an open-source learning management system widely deployed by educational institutions to facilitate online course delivery and student engagement. Its extensive plugin ecosystem and complex architecture have historically introduced significant attack surfaces, resulting in twenty-four recorded Common Vulnerabilities and Exposures. Security audits frequently identify critical flaws, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation or insecure default configurations. While the project maintains a responsible disclosure process, past incidents have highlighted risks associated with outdated third-party libraries and delayed patch adoption by administrators. These technical shortcomings allow attackers to compromise user data or disrupt academic services. Consequently, rigorous security hygiene, including timely updates and strict plugin management, remains essential for maintaining the integrity of Moodle-based educational environments against evolving cyber threats.

CVE IDTitleCVSSSeverityPublished
CVE-2022-50943 Moodle LMS 4.0 Cross-Site Scripting via course search.php — Moodle LMSCWE-79 6.1 Medium2026-05-10
CVE-2021-47857 Moodle 3.10.3 - 'label' Persistent Cross Site Scripting — MoodleCWE-79 7.2 High2026-01-21
CVE-2025-34032 Moodle LMS Jmol Plugin Cross-site Scripting (XSS) — Jmol PluginCWE-79 6.1AIMediumAI2025-06-24
CVE-2025-34031 Moodle LMS Jmol Plugin Path Traversal — Jmol PluginCWE-22 7.5AIHighAI2025-06-24
CVE-2025-53021 Moodle 授权问题漏洞 — MoodleCWE-384 4.2 Medium2025-06-24
CVE-2024-38277 moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys — MoodleCWE-324 7.5AIHighAI2024-06-18
CVE-2024-38276 moodle: CSRF risks due to misuse of confirm_sesskey — MoodleCWE-352 8.8AIHighAI2024-06-18
CVE-2024-38275 moodle: HTTP authorization header is preserved between "emulated redirects" — MoodleCWE-226 6.1AIMediumAI2024-06-18
CVE-2024-38274 moodle: stored XSS via calendar's event title when deleting the event — MoodleCWE-79 5.4AIMediumAI2024-06-18
CVE-2024-38273 moodle: BigBlueButton web service leaks meeting joining information to users who should not have access — MoodleCWE-284 5.4AIMediumAI2024-06-18
CVE-2024-33996 moodle: broken access control when setting calendar event type — MoodleCWE-20 4.3 -2024-05-31
CVE-2024-1439 Inadequate access control vulnerability in Moodle — LMSCWE-284 6.5 Medium2024-02-12
CVE-2012-1161 Moodle 信息泄露漏洞 — Moodle 4.3 -2019-11-14
CVE-2012-1170 Moodle 安全漏洞 — Moodle 7.5 -2019-11-14
CVE-2012-1169 Moodle 信息泄露漏洞 — Moodle 5.3 -2019-11-14
CVE-2012-1160 Moodle 安全漏洞 — Moodle 4.3 -2019-11-14
CVE-2012-1159 Moodle 信息泄露漏洞 — Moodle 4.3 -2019-11-14
CVE-2012-1158 Moodle 信息泄露漏洞 — Moodle 4.3 -2019-11-14
CVE-2012-1157 Moodle 安全漏洞 — Moodle 5.3 -2019-11-14
CVE-2012-1156 Moodle 日志信息泄露漏洞 — Moodle 7.5 -2019-11-14
CVE-2012-1168 Moodle 输入验证错误漏洞 — Moodle 8.2 -2019-11-14
CVE-2012-1155 Moodle 信息泄露漏洞 — Moodle 8.2 -2019-11-14
CVE-2019-10154 Moodle 访问控制错误漏洞 — moodleCWE-285 5.3 -2019-06-26
CVE-2019-10134 Moodle 输入验证错误漏洞 — moodleCWE-20 3.7 -2019-06-26
CVE-2019-10133 Moodle 输入验证错误漏洞 — moodleCWE-601 6.1 -2019-06-26

This page lists every published CVE security advisory associated with Moodle. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.