vendor

moodle

12 thingsrelated by NVD

Its products

moodle 12

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an…
CVE-2026-102588
Severity medium
A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user…
CVE-2026-102587
Severity low
A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a…
CVE-2026-102586
Severity medium
A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether…
CVE-2026-102585
Severity medium
A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade…
CVE-2026-102584
Severity medium
A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web…
CVE-2026-102583
Severity low
A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled…
CVE-2026-102582
Severity medium
A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting…
CVE-2026-102581
Severity medium
A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder…
CVE-2026-102580
Severity medium
A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile…
CVE-2026-102579
Severity medium
A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly…
CVE-2026-102578
Severity high
A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an…
CVE-2026-102577
Severity medium