Exposure of Moodle

LMS
74
exposure score
10,577
sites use
0
exploited
8
critical
Vexday analysis

Com 292 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o Moodle apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão de ameaças imediatas em ambiente real. No entanto, o EPSS elevado de 0,83 associado à CVE-2024-43425 indica probabilidade estatisticamente alta de exploração para essa vulnerabilidade específica, merecendo atenção prioritária nas equipes de patch management. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web com alto volume de conteúdo gerado por usuários, e as 7 CVEs de severidade crítica reforçam a necessidade de manter ciclos de atualização regulares. A baixa atividade no KEV não deve ser interpretada como ausência de risco, especialmente diante de scores EPSS elevados que sinalizam vulnerabilidades com perfil de interesse por parte de agentes maliciosos.

CVEs

293 results
CVE-2022-40208MEDIUMIn Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz atEPSS 0.6%CVE-2023-5549LOWMoodle: insufficient capability checks when updating the parent of a course categoryEPSS 0.6%CVE-2022-0984Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile fEPSS 0.6%CVE-2023-28334MEDIUMMoodle: users' name enumeration possible via idor on learning plans pageEPSS 0.6%CVE-2024-33999CRITICALmoodle: unsafe direct use of $_SERVER['HTTP_REFERER'] in admin/tool/mfa/index.phpEPSS 0.5%CVE-2023-5545LOWMoodle: auto-populated h5p author name causes a potential information leakEPSS 0.5%CVE-2020-1755In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote addreEPSS 0.5%CVE-2024-25980MEDIUMMsa-24-0003: h5p attempts report did not respect activity group settingsEPSS 0.5%CVE-2021-36401MEDIUMIn Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.EPSS 0.5%CVE-2024-43438HIGHMoodle: idor in feedback non-respondents report allows messaging arbitrary site usersEPSS 0.5%CVE-2021-36403MEDIUMIn Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which mayEPSS 0.5%CVE-2021-36402MEDIUMIn Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.EPSS 0.5%CVE-2025-26529HIGHStored XSS risk in admin live logEPSS 0.5%CVE-2017-7491In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview bloEPSS 0.5%CVE-2021-36399MEDIUMIn Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.EPSS 0.5%CVE-2021-36398MEDIUMIn moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.EPSS 0.5%CVE-2025-32044HIGHMoodle: unauthenticated rest api user data exposureEPSS 0.5%CVE-2023-5544MEDIUMMoodle: stored xss and potential idor risk in wiki commentsEPSS 0.5%CVE-2023-5547LOWMoodle: xss risk when previewing data in course upload toolEPSS 0.5%CVE-2023-5541LOWMoodle: xss risk when using csv grade import methodEPSS 0.5%