Moodle — система управления образовательными электронными курсами
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 713
CVE-2026-26046
A vulnerability was found in a Moodle TeX filter administrative settin ...
CVE-2026-26047
A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.
CVE-2026-26046
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
CVE-2026-26045
A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.
CVE-2026-26045
A flaw was identified in Moodle\u2019s backup restore functionality wh ...
CVE-2026-26045
A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.
BDU:2026-07358
Уязвимость компонента TeX Formula Editor виртуальной обучающей среды Moodle, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2026-07359
Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды
BDU:2026-07357
Уязвимость виртуальной обучающей среды Moodle, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код
GHSA-vwhw-vp9v-q9c9
Moodle vulnerable to Cross-site Scripting
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2026-26046 A vulnerability was found in a Moodle TeX filter administrative settin ... | CVSS3: 7.2 | 12% Средний | 7 месяцев назад | |
CVE-2026-26047 A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption. | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
CVE-2026-26046 A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server. | CVSS3: 7.2 | 12% Средний | 7 месяцев назад | |
CVE-2026-26045 A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server. | CVSS3: 7.2 | 1% Низкий | 7 месяцев назад | |
CVE-2026-26045 A flaw was identified in Moodle\u2019s backup restore functionality wh ... | CVSS3: 7.2 | 1% Низкий | 7 месяцев назад | |
CVE-2026-26045 A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server. | CVSS3: 7.2 | 1% Низкий | 7 месяцев назад | |
BDU:2026-07358 Уязвимость компонента TeX Formula Editor виртуальной обучающей среды Moodle, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
BDU:2026-07359 Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды | CVSS3: 7.2 | 12% Средний | 7 месяцев назад | |
BDU:2026-07357 Уязвимость виртуальной обучающей среды Moodle, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.2 | 1% Низкий | 7 месяцев назад | |
GHSA-vwhw-vp9v-q9c9 Moodle vulnerable to Cross-site Scripting | CVSS3: 5.4 | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу