CVE Tools

Moodle

192 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Moodle, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Moodle CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Moodle CVEs per month
MonthCVEs
2024-100
2024-1122
2024-121
2025-010
2025-029
2025-030
2025-0417
2025-050
2025-061
2025-070
2025-082
2025-091
2025-102
2025-110
2025-120
2026-012
2026-024
2026-031
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 192 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical116%
  • High4121%
  • Medium12364%
  • Low179%

Latest CVEs

The 15 most recently published vulnerabilities affecting Moodle.

  1. CVE-2025-49514Уязвимость виртуальной обучающей среды Moodle, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации8.6
  2. CVE-2026-26047Moodle: moodle: uncontrolled resource consumption in tex formula editor leading to denial of service6.5
  3. CVE-2026-26046Moodle: moodle: improper input sanitization in tex filter administration setting7.2
  4. CVE-2026-26045Moodle: moodle: improper validation in file restore functionality leading to remote code execution7.2
  5. CVE-2025-67850Moodle: moodle: cross-site scripting vulnerability via inadequate input filtering in formula editor7.3
  6. CVE-2025-67847Moodle: moodle: remote code execution via insufficient restore input validation8.8
  7. CVE-2021-47857Moodle 3.10.3 - 'label' Persistent Cross Site Scripting7.2
  8. CVE-2025-62401Moodle: possible to bypass timer in timed assignments5.4
  9. CVE-2025-62400Moodle: hidden group names visible to event creators4.3
  10. CVE-2025-49512Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю получить провести атаку межсайтового скриптинга (XSS)5.7
  11. BDU:2025-10104Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код6.3
  12. BDU:2025-10103Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код6.3
  13. CVE-2025-53021A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication...4.2
  14. CVE-2025-32045Moodle: hidden grades shown to users without permission on some grade reports5.3
  15. CVE-2025-32044Moodle: unauthenticated rest api user data exposure7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store