<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Moodle</title>
  <link>https://cvedaily.com/pages/tags/moodle.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/moodle.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Moodle</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:50 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2022-50943 – Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50943</guid>
    <pubDate>Sun, 10 May 2026 13:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-50943</strong></p>
  <p>Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30884 – mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically gene...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30884</guid>
    <pubDate>Wed, 18 Mar 2026 04:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30884</strong></p>
  <p>mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. Prior to versions 4.4.9 and 5.0.3, a teacher who holds `mod/customcert:manage` in any single course can read and silently overwrite certificate elements belonging to any other course in the Moodle installation. The `core_get_fragment` callback `editel…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26047 – A denial-of-service vulnerability was identified in Moodle’s TeX formula editor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26047</guid>
    <pubDate>Sat, 21 Feb 2026 06:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26047</strong></p>
  <p>A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26046 – A vulnerability was found in a Moodle TeX filter administrative setting where in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26046</guid>
    <pubDate>Sat, 21 Feb 2026 06:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26046</strong></p>
  <p>A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26045 – A flaw was identified in Moodle’s backup restore functionality where specially c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26045</guid>
    <pubDate>Sat, 21 Feb 2026 06:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26045</strong></p>
  <p>A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67857 – A flaw was found in moodle. During anonymous assignment submissions, user identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67857</guid>
    <pubDate>Tue, 03 Feb 2026 11:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67857</strong></p>
  <p>A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67856 – A flaw was found in Moodle. An authorization logic flaw, specifically due to inc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67856</guid>
    <pubDate>Tue, 03 Feb 2026 11:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67856</strong></p>
  <p>A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to, potentially leading to privilege escalation or unauthorized access to certain features.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67853 – A flaw was found in Moodle. A remote attacker could exploit a lack of proper rat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67853</guid>
    <pubDate>Tue, 03 Feb 2026 11:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67853</strong></p>
  <p>A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-67852 – A flaw was found in Moodle. An open redirect vulnerability in the OAuth login fl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67852</guid>
    <pubDate>Tue, 03 Feb 2026 11:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-67852</strong></p>
  <p>A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67851 – A flaw was found in moodle. This formula injection vulnerability occurs when dat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67851</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67851</guid>
    <pubDate>Tue, 03 Feb 2026 11:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67851</strong></p>
  <p>A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-1236</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67851">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67850 – A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67850</guid>
    <pubDate>Tue, 03 Feb 2026 11:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67850</strong></p>
  <p>A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or lea…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67849 – A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, cause...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67849</guid>
    <pubDate>Tue, 03 Feb 2026 11:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67849</strong></p>
  <p>A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67848 – A flaw was found in Moodle. This authentication bypass vulnerability allows susp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67848</guid>
    <pubDate>Tue, 03 Feb 2026 11:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67848</strong></p>
  <p>A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who s…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67847 – A flaw was found in Moodle. An attacker with access to the restore interface cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67847</guid>
    <pubDate>Fri, 23 Jan 2026 05:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67847</strong></p>
  <p>A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation could result in a full compromise of the Moodle application.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47857 – Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47857</guid>
    <pubDate>Wed, 21 Jan 2026 18:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47857</strong></p>
  <p>Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft a calendar event with malicious JavaScript in the subtitle track label to execute arbitrary code when users view the event.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62401 – An issue in Moodle’s timed assignment feature allowed students to bypass the tim...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62401</guid>
    <pubDate>Thu, 23 Oct 2025 12:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62401</strong></p>
  <p>An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62400 – Moodle exposed the names of hidden groups to users who had permission to create ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62400</guid>
    <pubDate>Thu, 23 Oct 2025 12:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62400</strong></p>
  <p>Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62399 – Moodle’s mobile and web service authentication endpoints did not sufficiently re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62399</guid>
    <pubDate>Thu, 23 Oct 2025 12:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62399</strong></p>
  <p>Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62396 – An error-handling issue in the Moodle router (r.php) could cause the application...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62396</guid>
    <pubDate>Thu, 23 Oct 2025 12:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62396</strong></p>
  <p>An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-548</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62394 – Moodle failed to verify enrolment status correctly when sending quiz notificatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62394</guid>
    <pubDate>Thu, 23 Oct 2025 12:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62394</strong></p>
  <p>Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-60507 – Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60507</guid>
    <pubDate>Tue, 21 Oct 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-60507</strong></p>
  <p>Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role can upload a PDF containing embedded JavaScript. The assistant outputs a direct HTML link to the uploaded file without sanitization. When other users (including Students or Administrators) click the link, the payload executes in their browser.</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60511 – Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Dire...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60511</guid>
    <pubDate>Tue, 21 Oct 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60511</strong></p>
  <p>Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in /blocks/openai_chat/api/completion.php. An authenticated student can impersonate another user's block (e.g., administrator) and send queries that are executed with that block's configuration. This can expose administrat…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60506 – Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60506</guid>
    <pubDate>Tue, 21 Oct 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60506</strong></p>
  <p>Moodle PDF Annotator plugin v1.5 release 9 allows stored cross-site scripting (XSS) via the Public Comments feature. An attacker with a low-privileged account (e.g., Student) can inject arbitrary JavaScript payloads into a comment. When any other user (Student, Teacher, or Admin) views the annotated PDF, the payload is executed in their browser, leading to session hijacking, credential theft, or…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53021 – A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53021</guid>
    <pubDate>Tue, 24 Jun 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53021</strong></p>
  <p>A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases pag…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-34032 – A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34032</guid>
    <pubDate>Tue, 24 Jun 2025 01:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-34032</strong></p>
  <p>A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the data parameter in jsmol.php. The application fails to properly sanitize user input before embedding it into the HTTP response, allowing an attacker to execute arbitrary JavaScript in the victim's browser by crafting a malicious link. This can be used to hijack user sessions or m…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34031 – A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34031</guid>
    <pubDate>Tue, 24 Jun 2025 01:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34031</strong></p>
  <p>A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read arbitrary files from the server's filesystem by crafting a malicious query value. This vulnerability can be exploited without authentication an…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-4513 – A vulnerability classified as problematic was found in Catalyst User Key Authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4513</guid>
    <pubDate>Sat, 10 May 2025 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-4513</strong></p>
  <p>A vulnerability classified as problematic was found in Catalyst User Key Authentication Plugin 20220819 on Moodle. Affected by this vulnerability is an unknown functionality of the file /auth/userkey/logout.php of the component Logout. The manipulation of the argument return leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3647 – A flaw was discovered in Moodle. Additional checks were required to ensure that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3647</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3647</strong></p>
  <p>A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3645 – A flaw was found in Moodle. Insufficient capability checks in a messaging web se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3645</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3645</strong></p>
  <p>A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3644 – A flaw was found in Moodle. Additional checks were required to prevent users fro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3644</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3644</strong></p>
  <p>A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3643 – A flaw was found in Moodle. The return URL in the policy tool required additiona...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3643</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3643</strong></p>
  <p>A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3642 – A flaw was found in Moodle. A remote code execution risk was identified in the M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3642</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3642</strong></p>
  <p>A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3641 – A flaw was found in Moodle. A remote code execution risk was identified in the M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3641</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3641</strong></p>
  <p>A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3640 – A flaw was found in Moodle. Insufficient capability checks made it possible for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3640</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3640</strong></p>
  <p>A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access some details, such as the full name and profile image URL, of other users they did not have permission to access.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3638 – A flaw was found in Moodle. The analysis request action in the Brickfield tool d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3638</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3638</strong></p>
  <p>A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-3637 – A security vulnerability was found in Moodle where confidential information that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3637</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-3637</strong></p>
  <p>A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and delete pages.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-598</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3636 – A flaw was found in Moodle. This vulnerability allows unauthorized users to acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3636</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3636</strong></p>
  <p>A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficient capability checks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-3635 – A security vulnerability was discovered in Moodle that allows anyone to duplicat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3635</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-3635</strong></p>
  <p>A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3628 – A flaw has was found in Moodle where anonymous assignment submissions can be de-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3628</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3628</strong></p>
  <p>A flaw has was found in Moodle where anonymous assignment submissions can be de-anonymized via search, revealing student identities.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3627 – A security vulnerability was discovered in Moodle that allows some users to acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3627</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3627</strong></p>
  <p>A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3625 – A security vulnerability was discovered in Moodle that can allow hackers to gain...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3625</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3625</strong></p>
  <p>A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32045 – A flaw has been identified in Moodle where insufficient capability checks in cer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32045</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32045</strong></p>
  <p>A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32044 – A flaw has been identified in Moodle where, on certain sites, unauthenticated us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32044</guid>
    <pubDate>Fri, 25 Apr 2025 15:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32044</strong></p>
  <p>A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with zend.exception_ignore_args = 1 in the php.ini file are not affected by this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3634 – A security vulnerability was discovered in Moodle that allows students to enroll...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3634</guid>
    <pubDate>Fri, 25 Apr 2025 14:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3634</strong></p>
  <p>A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finished two-step verification processes.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-48899 – A vulnerability was found in Moodle. Additional checks are required to ensure us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48899</guid>
    <pubDate>Wed, 20 Nov 2024 11:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-48899</strong></p>
  <p>A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45691 – A flaw was found in Moodle. When restricting access to a lesson activity with a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45691</guid>
    <pubDate>Wed, 20 Nov 2024 11:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45691</strong></p>
  <p>A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic hash" values.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-45690 – A flaw was found in Moodle. Additional checks were required to ensure users can ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45690</guid>
    <pubDate>Wed, 20 Nov 2024 11:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-45690</strong></p>
  <p>A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45689 – A flaw was found in Moodle. Dynamic tables did not enforce capability checks, wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45689</guid>
    <pubDate>Wed, 20 Nov 2024 11:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45689</strong></p>
  <p>A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-48901 – A vulnerability was found in Moodle. Additional checks are required to ensure us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48901</guid>
    <pubDate>Mon, 18 Nov 2024 12:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-48901</strong></p>
  <p>A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission to edit that report.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-48898 – A vulnerability was found in Moodle. Users with access to delete audiences from ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48898</guid>
    <pubDate>Mon, 18 Nov 2024 12:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-48898</strong></p>
  <p>A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have permission to delete from.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-48897 – A vulnerability was found in Moodle. Additional checks are required to ensure us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48897</guid>
    <pubDate>Mon, 18 Nov 2024 12:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-48897</strong></p>
  <p>A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to modify.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-48896 – A vulnerability was found in Moodle. It is possible for users with the "send mes...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48896</guid>
    <pubDate>Mon, 18 Nov 2024 12:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-48896</strong></p>
  <p>A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name format configured on the site.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-48900 – A vulnerability was found in Moodle. Additional checks are required to ensure us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48900</guid>
    <pubDate>Wed, 13 Nov 2024 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-48900</strong></p>
  <p>A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43439 – A flaw was found in moodle. H5P error messages require additional sanitizing to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43439</guid>
    <pubDate>Mon, 11 Nov 2024 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43439</strong></p>
  <p>A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43437 – A flaw was found in moodle. Insufficient sanitizing of data when performing a re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43437</guid>
    <pubDate>Mon, 11 Nov 2024 13:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43437</strong></p>
  <p>A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43435 – A flaw was found in moodle. Insufficient capability checks make it possible for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43435</guid>
    <pubDate>Mon, 11 Nov 2024 13:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43435</strong></p>
  <p>A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43433 – A flaw was found in moodle. Matrix room membership and power levels are incorrec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43433</guid>
    <pubDate>Mon, 11 Nov 2024 13:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43433</strong></p>
  <p>A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43432 – A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43432</guid>
    <pubDate>Mon, 11 Nov 2024 13:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43432</strong></p>
  <p>A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43430 – A flaw was found in moodle. External API access to Quiz can override contained i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43430</guid>
    <pubDate>Mon, 11 Nov 2024 13:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43430</strong></p>
  <p>A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-43429 – A flaw was found in moodle. Some hidden user profile fields are visible in grade...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43429</guid>
    <pubDate>Mon, 11 Nov 2024 13:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-43429</strong></p>
  <p>A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in users without the "view hidden user fields" capability having access to the information.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-43427 – A flaw was found in moodle. When creating an export of site administration prese...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43427</guid>
    <pubDate>Mon, 11 Nov 2024 13:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-43427</strong></p>
  <p>A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43440 – A flaw was found in moodle. A local file may include risks when restoring block ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43440</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43440</guid>
    <pubDate>Thu, 07 Nov 2024 14:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43440</strong></p>
  <p>A flaw was found in moodle. A local file may include risks when restoring block backups.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43440">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43434 – The bulk message sending feature in Moodle's Feedback module's non-respondents r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43434</guid>
    <pubDate>Thu, 07 Nov 2024 14:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43434</strong></p>
  <p>The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43431 – A vulnerability was found in Moodle. Insufficient capability checks made it poss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43431</guid>
    <pubDate>Thu, 07 Nov 2024 14:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43431</strong></p>
  <p>A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43428 – To address a cache poisoning risk in Moodle, additional validation for local sto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43428</guid>
    <pubDate>Thu, 07 Nov 2024 14:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43428</strong></p>
  <p>To address a cache poisoning risk in Moodle, additional validation for local storage was required.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43425 – A flaw was found in Moodle. Additional restrictions are required to avoid a remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43425</guid>
    <pubDate>Thu, 07 Nov 2024 14:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43425</strong></p>
  <p>A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34312 – Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cros...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34312</guid>
    <pubDate>Mon, 24 Jun 2024 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34312</strong></p>
  <p>Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component vplide.js.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37674 – Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37674</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37674</guid>
    <pubDate>Thu, 20 Jun 2024 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37674</strong></p>
  <p>Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37674">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38275 – The cURL wrapper in Moodle retained the original request headers when following ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38275</guid>
    <pubDate>Tue, 18 Jun 2024 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38275</strong></p>
  <p>The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-226</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34005 – In a shared hosting environment that has been misconfigured to allow access to o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34005</guid>
    <pubDate>Fri, 31 May 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34005</strong></p>
  <p>In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34004 – In a shared hosting environment that has been misconfigured to allow access to o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34004</guid>
    <pubDate>Fri, 31 May 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34004</strong></p>
  <p>In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34003 – In a shared hosting environment that has been misconfigured to allow access to o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34003</guid>
    <pubDate>Fri, 31 May 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34003</strong></p>
  <p>In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34002 – In a shared hosting environment that has been misconfigured to allow access to o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34002</guid>
    <pubDate>Fri, 31 May 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34002</strong></p>
  <p>In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local file include.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-28593 – The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwant...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28593</guid>
    <pubDate>Fri, 22 Mar 2024 15:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-28593</strong></p>
  <p>The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do things like insert images, play sounds or create different coloured and sized text." This page also says "Chat is due to be r…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-29374 – A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29374</guid>
    <pubDate>Thu, 21 Mar 2024 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-29374</strong></p>
  <p>A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-1439 – Inadequate access control in Moodle LMS. This vulnerability could allow a local ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1439</guid>
    <pubDate>Mon, 12 Feb 2024 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-1439</strong></p>
  <p>Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-5550 – In a shared hosting environment that has been misconfigured to allow access to o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5550</guid>
    <pubDate>Thu, 09 Nov 2023 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-5550</strong></p>
  <p>In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46858 – Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46858</guid>
    <pubDate>Sun, 29 Oct 2023 01:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46858</strong></p>
  <p>Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-4399 – The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4399</guid>
    <pubDate>Sat, 01 Jul 2023 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-4399</strong></p>
  <p>The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,2.0.6. This is due to missing or incorrect nonce validation on the user_data_synchronization_initiater(), course_synchronization_initiater(), users_link_to_moodle_synchronization(), connection_test_initiater(), admin_menus(), and subscribe_handler() function. This makes it possible…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35133 – An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35133</guid>
    <pubDate>Thu, 22 Jun 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35133</strong></p>
  <p>An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-35132 – A limited SQL injection risk was identified on the Mnet SSO access control page...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35132</guid>
    <pubDate>Thu, 22 Jun 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-35132</strong></p>
  <p>A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-35131 – Content on the groups page required additional sanitizing to prevent an XSS risk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35131</guid>
    <pubDate>Thu, 22 Jun 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-35131</strong></p>
  <p>Content on the groups page required additional sanitizing to prevent an XSS risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8 and 3.11 to 3.11.14.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-27131 – Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27131</guid>
    <pubDate>Tue, 16 May 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-27131</strong></p>
  <p>Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on the "Additional HTML Section" via "Header and Footer" parameter in /admin/settings.php. This vulnerability is leading an attacker to steal admin and all user account cookies by storing the malicious XSS payload in Header and Footer. NOTE: this is disputed by the vendor because the…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-30944 – The vulnerability was found Moodle which exists due to insufficient sanitization...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30944</guid>
    <pubDate>Tue, 02 May 2023 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-30944</strong></p>
  <p>The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-30943 – The vulnerability was found Moodle which exists because the application allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30943</guid>
    <pubDate>Tue, 02 May 2023 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-30943</strong></p>
  <p>The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-40208 – In Moodle, insufficient limitations in some quiz web services made it possible f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40208</guid>
    <pubDate>Fri, 24 Mar 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-40208</strong></p>
  <p>In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-28333 – The Mustache pix helper contained a potential Mustache injection risk if combine...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28333</guid>
    <pubDate>Thu, 23 Mar 2023 21:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-28333</strong></p>
  <p>The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36403 – In Moodle, in some circumstances, email notifications of messages could have the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36403</guid>
    <pubDate>Mon, 06 Mar 2023 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36403</strong></p>
  <p>In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-912</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36402 – In Moodle, Users' names required additional sanitizing in the account confirmati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36402</guid>
    <pubDate>Mon, 06 Mar 2023 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36402</strong></p>
  <p>In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36401 – In Moodle, ID numbers exported in HTML data formats required additional sanitizi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36401</guid>
    <pubDate>Mon, 06 Mar 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36401</strong></p>
  <p>In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36400 – In Moodle, insufficient capability checks made it possible to remove other users...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36400</guid>
    <pubDate>Mon, 06 Mar 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36400</strong></p>
  <p>In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36399 – In Moodle, ID numbers displayed in the quiz override screens required additional...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36399</guid>
    <pubDate>Mon, 06 Mar 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36399</strong></p>
  <p>In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36398 – In moodle, ID numbers displayed in the web service token list required additiona...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36398</guid>
    <pubDate>Mon, 06 Mar 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36398</strong></p>
  <p>In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36397 – In Moodle, insufficient capability checks meant message deletions were not limit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36397</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36397</guid>
    <pubDate>Mon, 06 Mar 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36397</strong></p>
  <p>In Moodle, insufficient capability checks meant message deletions were not limited to the current user.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36397">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36396 – In Moodle, insufficient redirect handling made it possible to blindly bypass cUR...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36396</guid>
    <pubDate>Mon, 06 Mar 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36396</strong></p>
  <p>In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-36395 – In Moodle, the file repository's URL parsing required additional recursion handl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36395</guid>
    <pubDate>Mon, 06 Mar 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-36395</strong></p>
  <p>In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36394 – In Moodle, a remote code execution risk was identified in the Shibboleth authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36394</guid>
    <pubDate>Mon, 06 Mar 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36394</strong></p>
  <p>In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36393 – In Moodle, an SQL injection risk was identified in the library fetching a user's...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36393</guid>
    <pubDate>Mon, 06 Mar 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36393</strong></p>
  <p>In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-36392 – In Moodle, an SQL injection risk was identified in the library fetching a user's...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36392</guid>
    <pubDate>Mon, 06 Mar 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-36392</strong></p>
  <p>In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-23923 – The vulnerability was found Moodle which exists due to insufficient limitations ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23923</guid>
    <pubDate>Fri, 17 Feb 2023 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-23923</strong></p>
  <p>The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23923">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
