Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 712
GHSA-f439-48pp-hm2q
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.
CVE-2022-50943
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.
CVE-2022-50943
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allo ...
CVE-2022-50943
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies.
GHSA-ggxq-2mg9-8966
Moodle has a Remote Code Execution risk via file restore
GHSA-cg8j-5cr2-568q
Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits
GHSA-4g4j-v56v-2w79
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
CVE-2026-26047
A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.
CVE-2026-26047
A denial-of-service vulnerability was identified in Moodle\u2019s TeX ...
CVE-2026-26046
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-f439-48pp-hm2q Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies. | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
CVE-2022-50943 Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies. | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
CVE-2022-50943 Moodle LMS 4.0 contains a cross-site scripting vulnerability that allo ... | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
CVE-2022-50943 Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can inject JavaScript code via the search field in course/search.php to execute arbitrary scripts in users' browsers and steal session cookies. | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
GHSA-ggxq-2mg9-8966 Moodle has a Remote Code Execution risk via file restore | CVSS3: 7.2 | 1% Низкий | 5 месяцев назад | |
GHSA-cg8j-5cr2-568q Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-4g4j-v56v-2w79 A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server. | CVSS3: 7.2 | 2% Низкий | 5 месяцев назад | |
CVE-2026-26047 A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-26047 A denial-of-service vulnerability was identified in Moodle\u2019s TeX ... | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-26046 A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server. | CVSS3: 7.2 | 2% Низкий | 5 месяцев назад |
Уязвимостей на страницу