CVE Tools

Moodle

630 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Moodle, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Moodle CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Moodle CVEs per month
MonthCVEs
2024-100
2024-1125
2024-121
2025-010
2025-029
2025-030
2025-0417
2025-050
2025-061
2025-070
2025-082
2025-091
2025-109
2025-110
2025-120
2026-012
2026-0212
2026-031
2026-040
2026-051
2026-060
2026-070
2026-080
2026-090

Severity

How the 630 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical234%
  • High9816%
  • Medium46173%
  • Low488%

Latest CVEs

The 15 most recently published vulnerabilities affecting Moodle.

  1. CVE-2022-50943Moodle LMS 4.0 Cross-Site Scripting via course search.php6.1
  2. CVE-2025-49514Уязвимость виртуальной обучающей среды Moodle, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации8.6
  3. CVE-2026-26047Moodle: moodle: uncontrolled resource consumption in tex formula editor leading to denial of service6.5
  4. CVE-2026-26046Moodle: moodle: improper input sanitization in tex filter administration setting7.2
  5. CVE-2026-26045Moodle: moodle: improper validation in file restore functionality leading to remote code execution7.2
  6. CVE-2025-67857Moodle: moodle: data exposure of user identifiers in urls4.3
  7. CVE-2025-67856Moodle: moodle: privilege escalation via incomplete role checks in badge awarding5.4
  8. CVE-2025-67855Mooodle: mooodle: information disclosure and script execution via reflected cross-site scripting5.4
  9. CVE-2025-67853Moodle: moodle: brute-force facilitation due to missing rate limiting in confirmation email service7.5
  10. CVE-2025-67852Moodle: moodle: open redirect vulnerability in oauth login flow allows redirection to malicious sites.3.5
  11. CVE-2025-67851Moodle: moodle: formula injection allows arbitrary formula execution via unescaped data export6.1
  12. CVE-2025-67850Moodle: moodle: cross-site scripting vulnerability via inadequate input filtering in formula editor7.3
  13. CVE-2025-67849Moodle: moodle: cross-site scripting (xss) via improper sanitization of ai prompt responses7.3
  14. CVE-2025-67848Moodle: moodle: authentication bypass via lti provider allows suspended users to gain unauthorized access.8.1
  15. CVE-2025-67847Moodle: moodle: remote code execution via insufficient restore input validation8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store