Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Moodle

First CVE: Apr 30, 2004Active for: 22 yearsTotal CVEs: 631
36.9
VTI Score
Medium

Moodle is a widely deployed open-source learning management system with a very large vulnerability footprint concentrated in a narrow product portfolio, making it one of the most represented vendors in the vulnerability landscape despite limited product diversity. The exposure recurs consistently across the core Moodle platform and its authentication and laboratory components through application-layer weakness classes including cross-site scripting, cross-site request forgery, and improper handling of sensitive information—vulnerabilities typical of web-facing educational and collaborative platforms. A meaningful share of Moodle's vulnerabilities reach serious severity, and the vendor's role in hosting student and institutional data means that even moderate-severity flaws can expose sensitive information at scale. Defenders should treat Moodle instances, particularly those exposed to the internet or handling sensitive academic records, as requiring regular patch cycles and defense-in-depth controls; live severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
631
Total CVEs
More Total CVEs than 100% of tracked vendors
9.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Moodle over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2004
22 years ago
Most Recent CVE
May 10, 2026
75 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (631 CVEs).

631 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-43425HIGH
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/updat
Nov 7, 20248.190NOYES
CVE-2021-36393CRITICAL
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
Mar 6, 20239.860NONO
CVE-2022-0332CRITICAL
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
Jan 25, 20229.859NOYES
CVE-2018-1133HIGH
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
May 25, 20188.856NOYES
CVE-2013-3630MEDIUM
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within
Nov 1, 20134.655NOYES
CVE-2021-21809CRITICAL
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An att
Jun 23, 20219.153NOYES
CVE-2022-35650HIGH
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This
Jul 25, 20227.550NONO
CVE-2017-2641CRITICAL
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
Mar 26, 20179.848NOYES
CVE-2020-14321HIGH
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
Aug 16, 20228.840NOYES
CVE-2019-3810MEDIUM
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, w
Mar 25, 20196.138NOYES
View all 631 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products631 CVEs
74%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (0.8%)
Network342 (54.2%)
Unknown283 (44.8%)
Physical0 (0.0%)
Adjacent Network1 (0.2%)
Attack Complexity
Low339 (53.7%)
High9 (1.4%)
Unknown283 (44.8%)
User Interaction
None235 (37.2%)
Unknown283 (44.8%)
Required113 (17.9%)
Privileges Required
Low147 (23.3%)
High15 (2.4%)
None186 (29.5%)
Unknown283 (44.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (631 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
0.8% of CVEs· 97th percentile
Nuclei
4 CVEs
0.6% of CVEs· 95th percentile
ExploitDB
23 CVEs
3.6% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Moodle.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Moodle — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Moodle's Products

View all 8 CNAs →

Top CWEs