Home / CVEs we hold for Moodle CVEs we hold for Moodle Records whose assigning authority named Moodle as the affected vendor. Newest identifiers first, capped at 200.
CVE-2025-34032 Moodle LMS Jmol Plugin Cross-site Scripting (XSS) Moodle Jmol Plugin CVE-2025-26533 SQL injection risk in course search module list filter moodle CVE-2025-26532 Teachers can evade trusttext config when restoring glossary entries moodle CVE-2025-26531 IDOR in badges allows disabling of arbitrary badges moodle CVE-2025-26527 Non-searchable tags can still be discovered on the tag search page and in the tags block moodle CVE-2025-26526 Feedback response viewing and deletions did not respect Separate Groups mode moodle CVE-2024-38277 moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys Moodle CVE-2024-38276 moodle: CSRF risks due to misuse of confirm_sesskey Moodle CVE-2024-38275 moodle: HTTP authorization header is preserved between "emulated redirects" Moodle CVE-2024-38274 moodle: stored XSS via calendar's event title when deleting the event Moodle CVE-2024-38273 moodle: BigBlueButton web service leaks meeting joining information to users who should not have access Moodle CVE-2024-33996 moodle: broken access control when setting calendar event type Moodle CVE-2024-1439 Inadequate access control vulnerability in Moodle Moodle LMS CVE-2022-50943 Moodle LMS 4.0 Cross-Site Scripting via course search.php Moodle LMS CVE-2022-39183 Moodle Plugin - SAML Auth Open Redirect Moodle Plugin - SAML Auth CVE-2021-47857 Moodle 3.10.3 - 'label' Persistent Cross Site Scripting Moodle CVE-2020-36633 moodle-block_sitenews block_sitenews.php get_content cross-site request forgery n/a moodle-block_sitenews 150 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.