Moodle

Vendor:

First CVE: Apr 30, 2004 · Active for 22 years

629
Total CVEs
More Total CVEs than 100% of tracked products
27.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Moodle over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2004
22 years ago
Most Recent CVE
May 10, 2026
78 days ago

CVE Severity & Scoring

Moodle629 CVEs
All CVEs352,727 CVEs
LowMediumHighCritical
Attack Vector
Local5 (0.8%)
Network340 (54.1%)
Unknown283 (45.0%)
Physical0 (0.0%)
Adjacent Network1 (0.2%)
Attack Complexity
Low337 (53.6%)
High9 (1.4%)
Unknown283 (45.0%)
User Interaction
None235 (37.4%)
Unknown283 (45.0%)
Required111 (17.6%)
Privileges Required
Low147 (23.4%)
High15 (2.4%)
None184 (29.3%)
Unknown283 (45.0%)

Top CVEs

Signals from CVEs in this product scope (629 CVEs).

629 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/updat
Nov 7, 20248.190NOYES
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
Mar 6, 20239.860NONO
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
Jan 25, 20229.859NOYES
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
May 25, 20188.856NOYES
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within
Nov 1, 20134.655NOYES
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An att
Jun 23, 20219.153NOYES
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This
Jul 25, 20227.550NONO
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
Mar 26, 20179.848NOYES
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
Aug 16, 20228.840NOYES
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, w
Mar 25, 20196.138NOYES

Exploit Exposure

Signals from CVEs in this product scope (629 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
0.8% of CVEs· 96th percentile
Nuclei
4 CVEs
0.6% of CVEs· 96th percentile
ExploitDB
23 CVEs
3.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (629 CVEs).

Media Mentions

Signals from CVEs in this product scope (629 CVEs).

Top CNAs Publishing CVEs For Moodle

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.1.0107.20.3%00
4.4.056.60.4%00
4.3.315.40.5%00
4.3.015.40.6%00
4.2.214.30.4%00
4.2.036.60.8%00
4.1.196.60.8%00
4.1.0126.60.8%00
4.0.126.12.7%01
4.0.0166.21.9%01
3.9.715.40.8%00
3.9.0116.62.3%01
3.8.114.30.6%00
3.8.024.80.5%00
3.6.115.41.1%00
3.6.015.41.1%00
3.4.035.85.9%01
3.3.345.74.7%01
3.3.255.83.9%01
3.3.185.82.8%01