Exposure of Moodle

LMS
78
exposure score
12,726
sites use
0
exploited
8
critical
Vexday analysis

Com 292 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o Moodle apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão de ameaças imediatas em ambiente real. No entanto, o EPSS elevado de 0,83 associado à CVE-2024-43425 indica probabilidade estatisticamente alta de exploração para essa vulnerabilidade específica, merecendo atenção prioritária nas equipes de patch management. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web com alto volume de conteúdo gerado por usuários, e as 7 CVEs de severidade crítica reforçam a necessidade de manter ciclos de atualização regulares. A baixa atividade no KEV não deve ser interpretada como ausência de risco, especialmente diante de scores EPSS elevados que sinalizam vulnerabilidades com perfil de interesse por parte de agentes maliciosos.

CVEs

293 results
CVE-2024-43425HIGHMoodle: remote code execution via calculated question typesEPSS 83.2%CVE-2021-36393In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.EPSS 52.3%CVE-2022-35650The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks rEPSS 49.1%CVE-2022-0332A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for EPSS 44.9%CVE-2018-1133An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server,EPSS 31.9%CVE-2021-21809HIGHA command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requesEPSS 24.2%CVE-2020-14321In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.EPSS 16.7%CVE-2018-1042Moodle 3.x has Server Side Request Forgery in the filepicker.EPSS 15.6%CVE-2017-2641In Moodle 2.x and 3.x, SQL injection can occur via user preferences.EPSS 14.5%CVE-2019-3810MEDIUMA flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ EPSS 13.9%CVE-2022-35649The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter EPSS 8.4%CVE-2021-36394In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.EPSS 7.0%CVE-2023-30943MEDIUMMoodle: tinymce loaders susceptible to arbitrary folder creationEPSS 6.6%CVE-2022-30600A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.EPSS 5.1%CVE-2022-35653A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-suppliedEPSS 4.5%CVE-2018-14630HIGHmoodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution.EPSS 4.4%CVE-2020-25627The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed inEPSS 3.7%CVE-2019-14830A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoEPSS 3.3%CVE-2020-10738HIGHA flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versionEPSS 3.1%CVE-2021-3943A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code executiEPSS 2.4%