Moodle is a widely deployed open-source learning management system with a very large vulnerability footprint concentrated in a narrow product portfolio, making it one of the most represented vendors in the vulnerability landscape despite limited product diversity. The exposure recurs consistently across the core Moodle platform and its authentication and laboratory components through application-layer weakness classes including cross-site scripting, cross-site request forgery, and improper handling of sensitive information—vulnerabilities typical of web-facing educational and collaborative platforms. A meaningful share of Moodle's vulnerabilities reach serious severity, and the vendor's role in hosting student and institutional data means that even moderate-severity flaws can expose sensitive information at scale. Defenders should treat Moodle instances, particularly those exposed to the internet or handling sensitive academic records, as requiring regular patch cycles and defense-in-depth controls; live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Moodle over time
Signals from CVEs in this vendor scope (631 CVEs).
631 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43425HIGH A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/updat | Nov 7, 2024 | 8.1 | 90 | NO | YES |
CVE-2021-36393CRITICAL In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. | Mar 6, 2023 | 9.8 | 60 | NO | NO |
CVE-2022-0332CRITICAL A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data. | Jan 25, 2022 | 9.8 | 59 | NO | YES |
CVE-2018-1133HIGH An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection. | May 25, 2018 | 8.8 | 56 | NO | YES |
CVE-2013-3630MEDIUM Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within | Nov 1, 2013 | 4.6 | 55 | NO | YES |
CVE-2021-21809CRITICAL A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An att | Jun 23, 2021 | 9.1 | 53 | NO | YES |
CVE-2022-35650HIGH The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This | Jul 25, 2022 | 7.5 | 50 | NO | NO |
CVE-2017-2641CRITICAL In Moodle 2.x and 3.x, SQL injection can occur via user preferences. | Mar 26, 2017 | 9.8 | 48 | NO | YES |
CVE-2020-14321HIGH In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course. | Aug 16, 2022 | 8.8 | 40 | NO | YES |
CVE-2019-3810MEDIUM A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, w | Mar 25, 2019 | 6.1 | 38 | NO | YES |
Signals from CVEs in this vendor scope (631 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Moodle.
Media articles that mention a CVE ID that affects a product developed by Moodle — matched by CVE ID, not by vendor name.