Moodle
Vendor:
First CVE: Apr 30, 2004 · Active for 22 years
629
Total CVEs
More Total CVEs than 100% of tracked products
27.3
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Moodle over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2004
22 years ago
Most Recent CVE
May 10, 2026
78 days ago
CVE Severity & Scoring
Moodle629 CVEs
74%
17%
All CVEs352,727 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (0.8%)
Network340 (54.1%)
Unknown283 (45.0%)
Physical0 (0.0%)
Adjacent Network1 (0.2%)
Attack Complexity
Low337 (53.6%)
High9 (1.4%)
Unknown283 (45.0%)
User Interaction
None235 (37.4%)
Unknown283 (45.0%)
Required111 (17.6%)
Privileges Required
Low147 (23.4%)
High15 (2.4%)
None184 (29.3%)
Unknown283 (45.0%)
Top CVEs
Signals from CVEs in this product scope (629 CVEs).
629 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43425HIGH A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/updat | Nov 7, 2024 | 8.1 | 90 | NO | YES |
CVE-2021-36393CRITICAL In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. | Mar 6, 2023 | 9.8 | 60 | NO | NO |
CVE-2022-0332CRITICAL A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data. | Jan 25, 2022 | 9.8 | 59 | NO | YES |
CVE-2018-1133HIGH An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection. | May 25, 2018 | 8.8 | 56 | NO | YES |
CVE-2013-3630MEDIUM Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within | Nov 1, 2013 | 4.6 | 55 | NO | YES |
CVE-2021-21809CRITICAL A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An att | Jun 23, 2021 | 9.1 | 53 | NO | YES |
CVE-2022-35650HIGH The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This | Jul 25, 2022 | 7.5 | 50 | NO | NO |
CVE-2017-2641CRITICAL In Moodle 2.x and 3.x, SQL injection can occur via user preferences. | Mar 26, 2017 | 9.8 | 48 | NO | YES |
CVE-2020-14321HIGH In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course. | Aug 16, 2022 | 8.8 | 40 | NO | YES |
CVE-2019-3810MEDIUM A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, w | Mar 25, 2019 | 6.1 | 38 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (629 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
0.8% of CVEs· 96th percentile
Nuclei
4 CVEs
0.6% of CVEs· 96th percentile
ExploitDB
23 CVEs
3.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (629 CVEs).
Media Mentions
Signals from CVEs in this product scope (629 CVEs).
Top CNAs Publishing CVEs For Moodle
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.1.0 | 10 | 7.2 | 0.3% | 0 | 0 |
| 4.4.0 | 5 | 6.6 | 0.4% | 0 | 0 |
| 4.3.3 | 1 | 5.4 | 0.5% | 0 | 0 |
| 4.3.0 | 1 | 5.4 | 0.6% | 0 | 0 |
| 4.2.2 | 1 | 4.3 | 0.4% | 0 | 0 |
| 4.2.0 | 3 | 6.6 | 0.8% | 0 | 0 |
| 4.1.1 | 9 | 6.6 | 0.8% | 0 | 0 |
| 4.1.0 | 12 | 6.6 | 0.8% | 0 | 0 |
| 4.0.1 | 2 | 6.1 | 2.7% | 0 | 1 |
| 4.0.0 | 16 | 6.2 | 1.9% | 0 | 1 |
| 3.9.7 | 1 | 5.4 | 0.8% | 0 | 0 |
| 3.9.0 | 11 | 6.6 | 2.3% | 0 | 1 |
| 3.8.1 | 1 | 4.3 | 0.6% | 0 | 0 |
| 3.8.0 | 2 | 4.8 | 0.5% | 0 | 0 |
| 3.6.1 | 1 | 5.4 | 1.1% | 0 | 0 |
| 3.6.0 | 1 | 5.4 | 1.1% | 0 | 0 |
| 3.4.0 | 3 | 5.8 | 5.9% | 0 | 1 |
| 3.3.3 | 4 | 5.7 | 4.7% | 0 | 1 |
| 3.3.2 | 5 | 5.8 | 3.9% | 0 | 1 |
| 3.3.1 | 8 | 5.8 | 2.8% | 0 | 1 |