Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.15.220242025202620272028

Недавние уязвимости Moodle

Количество 2 712

debian логотип

CVE-2026-26046

5 месяцев назад

A vulnerability was found in a Moodle TeX filter administrative settin ...

CVSS3: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2026-26046

5 месяцев назад

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2026-26047

5 месяцев назад

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-26045

5 месяцев назад

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

CVSS3: 7.2
EPSS: Низкий
debian логотип

CVE-2026-26045

5 месяцев назад

A flaw was identified in Moodle\u2019s backup restore functionality wh ...

CVSS3: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2026-26045

5 месяцев назад

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

CVSS3: 7.2
EPSS: Низкий
fstec логотип

BDU:2026-07357

5 месяцев назад

Уязвимость виртуальной обучающей среды Moodle, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.2
EPSS: Низкий
fstec логотип

BDU:2026-07359

5 месяцев назад

Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.2
EPSS: Низкий
fstec логотип

BDU:2026-07358

5 месяцев назад

Уязвимость компонента TeX Formula Editor виртуальной обучающей среды Moodle, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vwhw-vp9v-q9c9

6 месяцев назад

Moodle vulnerable to Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2026-26046

A vulnerability was found in a Moodle TeX filter administrative settin ...

CVSS3: 7.2
2%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-26046

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
2%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-26047

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to consume excessive server resources. An authenticated user could abuse this behavior to degrade performance or cause service interruption.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-26045

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

CVSS3: 7.2
1%
Низкий
5 месяцев назад
debian логотип
CVE-2026-26045

A flaw was identified in Moodle\u2019s backup restore functionality wh ...

CVSS3: 7.2
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-26045

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

CVSS3: 7.2
1%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-07357

Уязвимость виртуальной обучающей среды Moodle, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.2
1%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-07359

Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.2
2%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-07358

Уязвимость компонента TeX Formula Editor виртуальной обучающей среды Moodle, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-vwhw-vp9v-q9c9

Moodle vulnerable to Cross-site Scripting

CVSS3: 5.4
0%
Низкий
6 месяцев назад

Уязвимостей на страницу


Поделиться