Moodle-project
9 CVEs tracked since 2025. Since Feb 2025, none of them reached CISA KEV.
Moodle-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-02 | 9 | 0 |
Products
The products that kept showing up in Moodle-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 9 most recently published vulnerabilities affecting Moodle-project.
- CVE-2025-26533SQL injection risk in course search module list filter8.1
- CVE-2025-26532Teachers can evade trusttext config when restoring glossary entries3.1
- CVE-2025-26531IDOR in badges allows disabling of arbitrary badges3.1
- CVE-2025-26530Reflected XSS via question bank filter8.3
- CVE-2025-26529Stored XSS risk in admin live log8.3
- CVE-2025-26528Stored XSS in ddimageortext question type3.4
- CVE-2025-26527Non-searchable tags can still be discovered on the tag search page and in the tags block5.3
- CVE-2025-26526Feedback response viewing and deletions did not respect Separate Groups mode6.5
- CVE-2025-26525Arbitrary file read risk through pdfTeX8.6
The record
- Peak rank
- #85 in Feb 2025
- Busiest month shown
- Feb 2025, 9 CVEs
- Months with a KEV entry
- 0 since Feb 2025
- Monthly snapshots
- 1 since 2025