Exposure of Moodle

LMS
74
exposure score
10,577
sites use
0
exploited
8
critical
Vexday analysis

Com 292 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o Moodle apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão de ameaças imediatas em ambiente real. No entanto, o EPSS elevado de 0,83 associado à CVE-2024-43425 indica probabilidade estatisticamente alta de exploração para essa vulnerabilidade específica, merecendo atenção prioritária nas equipes de patch management. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web com alto volume de conteúdo gerado por usuários, e as 7 CVEs de severidade crítica reforçam a necessidade de manter ciclos de atualização regulares. A baixa atividade no KEV não deve ser interpretada como ausência de risco, especialmente diante de scores EPSS elevados que sinalizam vulnerabilidades com perfil de interesse por parte de agentes maliciosos.

CVEs

293 results
CVE-2020-25628The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7EPSS 1.0%CVE-2018-1136An issue was discovered in Moodle 3.x. An authenticated user is allowed to add HTML blocks containing scripts to their Dashboard; this is noEPSS 1.0%CVE-2017-12157In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.EPSS 1.0%CVE-2016-7038In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.EPSS 1.0%CVE-2023-23923Moodle: possible to set the preferred "start page" of other usersEPSS 1.0%CVE-2024-25978HIGHMsa-24-0001: denial of service risk in file picker unzip functionalityEPSS 0.9%CVE-2020-25631A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapEPSS 0.9%CVE-2022-0983An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachEPSS 0.9%CVE-2019-14884MEDIUMA vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal eEPSS 0.9%CVE-2021-32474An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this reEPSS 0.9%CVE-2019-3848MEDIUMA vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event infoEPSS 0.9%CVE-2012-1170Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thoroughEPSS 0.9%CVE-2020-14322In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of deniEPSS 0.9%CVE-2019-3852MEDIUMA vulnerability was found in moodle before version 3.6.3. The get_with_capability_join and get_users_by_capability functions were not takingEPSS 0.9%CVE-2022-40315CRITICALA limited SQL injection risk was identified in the "browse list of users" site administration page.EPSS 0.9%CVE-2024-4186CRITICALEdwiser Bridge <= 3.0.5 - Authentication Bypass due to Missing Empty Value CheckEPSS 0.9%CVE-2021-40694Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system accouEPSS 0.9%CVE-2019-10133LOWA flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not EPSS 0.9%CVE-2022-30596A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent EPSS 0.9%CVE-2019-10189MEDIUMA flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groupEPSS 0.9%