CVE-2025-26527
- EPSS 0.37%
- Veröffentlicht 24.02.2025 20:15:33
- Zuletzt bearbeitet 08.08.2025 19:40:08
Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.
CVE-2025-26528
- EPSS 0.71%
- Veröffentlicht 24.02.2025 20:15:33
- Zuletzt bearbeitet 08.08.2025 19:38:31
The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.
CVE-2025-26529
- EPSS 0.96%
- Veröffentlicht 24.02.2025 20:15:33
- Zuletzt bearbeitet 08.08.2025 19:37:24
Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.
CVE-2025-26530
- EPSS 0.96%
- Veröffentlicht 24.02.2025 20:15:33
- Zuletzt bearbeitet 11.08.2025 14:55:22
The question bank filter required additional sanitizing to prevent a reflected XSS risk.
CVE-2025-26531
- EPSS 0.35%
- Veröffentlicht 24.02.2025 20:15:33
- Zuletzt bearbeitet 07.08.2025 00:06:02
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
CVE-2024-45689
- EPSS 0.13%
- Veröffentlicht 20.11.2024 11:15:05
- Zuletzt bearbeitet 02.06.2025 15:33:57
A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability to retrieve information they did not have permission to access.
CVE-2024-45690
- EPSS 0.39%
- Veröffentlicht 20.11.2024 11:15:05
- Zuletzt bearbeitet 02.06.2025 15:34:48
A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.
CVE-2024-45691
- EPSS 0.39%
- Veröffentlicht 20.11.2024 11:15:05
- Zuletzt bearbeitet 02.06.2025 15:35:23
A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be bypassed or less secure due to a loose comparison in the password-checking logic. This issue only affected passwords set to "magic ha...
CVE-2024-48899
- EPSS 0.19%
- Veröffentlicht 20.11.2024 11:15:05
- Zuletzt bearbeitet 02.06.2025 15:36:03
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
CVE-2024-48896
- EPSS 0.31%
- Veröffentlicht 18.11.2024 12:15:18
- Zuletzt bearbeitet 20.11.2024 14:47:12
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not otherwise have access to via an error message in Messaging. Note: The name returned follows the full name fo...