Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

github логотип

GHSA-f439-48pp-hm2q

3 месяца назад

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-50943

3 месяца назад

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-50943

3 месяца назад

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allo ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2022-50943

3 месяца назад

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4g4j-v56v-2w79

5 месяцев назад

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-cg8j-5cr2-568q

5 месяцев назад

Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-ggxq-2mg9-8966

5 месяцев назад

Moodle has a Remote Code Execution risk via file restore

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-26047

5 месяцев назад

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-26047

5 месяцев назад

A denial-of-service vulnerability was identified in Moodle\u2019s TeX ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-26046

5 месяцев назад

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-f439-48pp-hm2q

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.

CVSS3: 6.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2022-50943

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.

CVSS3: 6.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2022-50943

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allo ...

CVSS3: 6.1
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2022-50943

Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-4g4j-v56v-2w79

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
2%
Низкий
5 месяцев назад
github логотип
GHSA-cg8j-5cr2-568q

Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-ggxq-2mg9-8966

Moodle has a Remote Code Execution risk via file restore

CVSS3: 7.2
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-26047

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-26047

A denial-of-service vulnerability was identified in Moodle\u2019s TeX ...

CVSS3: 6.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-26046

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
2%
Низкий
5 месяцев назад

Уязвимостей на страницу


Поделиться