Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"
Moodle

Moodleсистема управления образовательными электронными курсами

Релизный цикл, информация об уязвимостях

Продукт: Moodle
Вендор: moodle

График релизов

4.55.05.120242025202620272028

Недавние уязвимости Moodle

Количество 2 647

nvd логотип

CVE-2025-3625

9 месяцев назад

A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2025-32045

9 месяцев назад

A flaw has been identified in Moodle where insufficient capability che ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-32045

9 месяцев назад

A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-32044

9 месяцев назад

A flaw has been identified in Moodle where, on certain sites, unauthen ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-32044

9 месяцев назад

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with zend.exception_ignore_args = 1 in the php.ini file are not affected by this vulnerability.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-3645

9 месяцев назад

A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-32045

9 месяцев назад

A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-3625

9 месяцев назад

A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2025-3635

9 месяцев назад

A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.

CVSS3: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2025-3627

9 месяцев назад

A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2025-3625

A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).

CVSS3: 7.1
0%
Низкий
9 месяцев назад
debian логотип
CVE-2025-32045

A flaw has been identified in Moodle where insufficient capability che ...

CVSS3: 5.3
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-32045

A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
debian логотип
CVE-2025-32044

A flaw has been identified in Moodle where, on certain sites, unauthen ...

CVSS3: 7.5
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-32044

A flaw has been identified in Moodle where, on certain sites, unauthenticated users could retrieve sensitive user data—including names, contact information, and hashed passwords—via stack traces returned by specific API calls. Sites with PHP configured with zend.exception_ignore_args = 1 in the php.ini file are not affected by this vulnerability.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-3645

A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses.

CVSS3: 4.3
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-32045

A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-3625

A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from logging into their accounts, even after they had completed two-factor authentication (2FA).

CVSS3: 7.1
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-3635

A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.

CVSS3: 3.5
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-3627

A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).

CVSS3: 4.3
0%
Низкий
9 месяцев назад

Уязвимостей на страницу


Поделиться