Exposição de Moodle

LMS
74
score de exposição
10.577
sites usam
0
em exploração
8
críticos
Análise Vexday

Com 292 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o Moodle apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão de ameaças imediatas em ambiente real. No entanto, o EPSS elevado de 0,83 associado à CVE-2024-43425 indica probabilidade estatisticamente alta de exploração para essa vulnerabilidade específica, merecendo atenção prioritária nas equipes de patch management. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web com alto volume de conteúdo gerado por usuários, e as 7 CVEs de severidade crítica reforçam a necessidade de manter ciclos de atualização regulares. A baixa atividade no KEV não deve ser interpretada como ausência de risco, especialmente diante de scores EPSS elevados que sinalizam vulnerabilidades com perfil de interesse por parte de agentes maliciosos.

CVEs

293 resultados
CVE-2021-32476A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3EPSS 1.1%CVE-2019-14882LOWA vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit pEPSS 1.1%CVE-2021-20283The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view thatEPSS 1.1%CVE-2017-12156Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.EPSS 1.1%CVE-2022-35652An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attackeEPSS 1.1%CVE-2019-10134MEDIUMA flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly EPSS 1.1%CVE-2017-2645In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.EPSS 1.1%CVE-2017-2644In Moodle 3.x, XSS can occur via evidence of prior learning.EPSS 1.1%CVE-2017-7490In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.EPSS 1.0%CVE-2022-35651A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM trEPSS 1.0%CVE-2025-3642HIGHMoodle: authenticated remote code execution risk in the moodle lms equella repositoryEPSS 1.0%CVE-2021-32473It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.10 to 3.10.3, 3.9 to EPSS 1.0%CVE-2019-3849MEDIUMA vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses oEPSS 1.0%CVE-2017-2576In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.EPSS 1.0%CVE-2018-1134An issue was discovered in Moodle 3.x. Students who submitted assignments and exported them to portfolios can download any stored Moodle filEPSS 1.0%CVE-2021-43560A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capabiliEPSS 1.0%CVE-2021-20279The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.EPSS 1.0%CVE-2020-1756In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.EPSS 1.0%CVE-2018-1044In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.EPSS 1.0%CVE-2025-3641HIGHMoodle: authenticated remote code execution risk in the moodle lms dropbox repositoryEPSS 1.0%