Known vulnerabilities in Moodle - page 8

Vendor: moodle.org
Software: Moodle
Software CPE: cpe:2.3:a:moodle_org:moodle:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 605
Public exploits: 26
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Moodle Moodle is affected by 605 known vulnerabilities: 28 high, 241 medium, 335 low Critical High Medium Low

Vulnerabilities (605)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU86741 - Improper Access Control
CVE-2024-25981
CWE-284 Low
No
No
4.1.9, 4.2.6, 4.3.3 23.02.2024 SB2024022309
SB2024022313
#VU86739 - Authorization Bypass Through User-Controlled Key
CVE-2024-25983
CWE-639 Low
No
No
4.1.9, 4.2.6, 4.3.3 23.02.2024 SB2024022309
SB2024022313
#VU84629 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-6661
CWE-94 Medium
No
No
3.9.25, 3.11.18, 4.0.12, 4.1.7, 4.2.4, 4.3.1 21.12.2023 SB2023122113
#VU84628 - Improper input validation
CVE-2023-6662
CWE-20 Medium
No
No
3.9.25, 3.11.18, 4.0.12, 4.1.7, 4.2.4, 4.3.1 21.12.2023 SB2023122113
#VU84627 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-6663
CWE-94 Medium
No
No
3.9.25, 3.11.18, 4.0.12, 4.1.7, 4.2.4, 4.3.1 21.12.2023 SB2023122113
#VU84626 - Exposure of sensitive information to an unauthorized actor
CVE-2023-6664
CWE-200 Medium
No
No
3.9.25, 3.11.18, 4.0.12, 4.1.7, 4.2.4, 4.3.1 21.12.2023 SB2023122113
#VU84625 - Exposure of sensitive information to an unauthorized actor
CVE-2023-6667
CWE-200 Medium
No
No
3.9.25, 3.11.18, 4.0.12, 4.1.7, 4.2.4, 4.3.1 21.12.2023 SB2023122113
#VU84624 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-6665
CWE-79 Low
No
No
4.2.4, 4.3.1 21.12.2023 SB2023122113
#VU84623 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-6666
CWE-79 Low
No
No
4.2.4, 4.3.1 21.12.2023 SB2023122113
#VU84622 - Exposure of sensitive information to an unauthorized actor
CVE-2023-6668
CWE-200 Medium
No
No
3.9.25, 3.11.18, 4.0.12, 4.1.7, 4.2.4, 4.3.1 21.12.2023 SB2023122113
#VU84621 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-6669
CWE-79 Low
No
No
3.9.25, 3.11.18, 4.0.12, 4.1.7, 4.2.4, 4.3.1 21.12.2023 SB2023122113
#VU84620 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-6670
CWE-79 Low
No
No
4.2.4, 4.3.1 21.12.2023 SB2023122113
#VU82196 - Exposure of sensitive information to an unauthorized actor
CVE-2023-5551
CWE-200 Low
No
No
3.9.24, 3.11.17, 4.0.11, 4.1.6, 4.2.3 18.10.2023 SB2023101832
#VU82195 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-5550
CWE-94 Medium
No
No
3.9.24, 3.11.17, 4.0.11, 4.1.6, 4.2.3 18.10.2023 SB2023101832
#VU82194 - Improper Access Control
CVE-2023-5549
CWE-284 Low
No
No
3.9.24, 3.11.17, 4.0.11, 4.1.6, 4.2.3 18.10.2023 SB2023101832
#VU82193 - Acceptance of Extraneous Untrusted Data With Trusted Data
CVE-2023-5548
CWE-349 Medium
No
No
3.9.24, 3.11.17, 4.0.11, 4.1.6, 4.2.3 18.10.2023 SB2023101832
#VU82191 - Improper Access Control
CVE-2023-5543
CWE-284 Medium
No
No
4.0.11, 4.1.6, 4.2.3 18.10.2023 SB2023101832
#VU82190 - Exposure of sensitive information to an unauthorized actor
CVE-2023-5545
CWE-200 Medium
No
No
3.9.24, 3.11.17, 4.0.11, 4.1.6, 4.2.3 18.10.2023 SB2023101832
#VU82189 - Improper Access Control
CVE-2023-5542
CWE-284 Low
No
No
4.2.3 18.10.2023 SB2023101832
#VU82179 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-5547
CWE-79 Low
No
No
3.9.24, 3.11.17, 4.0.11, 4.1.6, 4.2.3 18.10.2023 SB2023101832


Showing elements 141 - 160 out of 605