Exposição de Moodle

LMS
74
score de exposição
10.577
sites usam
0
em exploração
8
críticos
Análise Vexday

Com 292 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o Moodle apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão de ameaças imediatas em ambiente real. No entanto, o EPSS elevado de 0,83 associado à CVE-2024-43425 indica probabilidade estatisticamente alta de exploração para essa vulnerabilidade específica, merecendo atenção prioritária nas equipes de patch management. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão comum em plataformas web com alto volume de conteúdo gerado por usuários, e as 7 CVEs de severidade crítica reforçam a necessidade de manter ciclos de atualização regulares. A baixa atividade no KEV não deve ser interpretada como ausência de risco, especialmente diante de scores EPSS elevados que sinalizam vulnerabilidades com perfil de interesse por parte de agentes maliciosos.

CVEs

293 resultados
CVE-2023-28332Moodle: algebra filter xss when filter is misconfiguredEPSS 0.6%CVE-2024-43434HIGHMoodle: csrf risk in feedback non-respondents reportEPSS 0.6%CVE-2019-14828A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where users with thEPSS 0.6%CVE-2021-43559A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related bEPSS 0.6%CVE-2021-40692Insufficient capability checks made it possible for teachers to download users outside of their courses.EPSS 0.6%CVE-2020-1691In Moodle 3.8, messages required extra sanitizing before updating the conversation overview, to prevent the risk of stored cross-site scriptEPSS 0.6%CVE-2022-0335A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge aliEPSS 0.6%CVE-2024-25983LOWMsa-24-0006: idor on dashboard comments blockEPSS 0.6%CVE-2021-32475ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3EPSS 0.6%CVE-2022-40316MEDIUMThe H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers abEPSS 0.6%CVE-2024-25979MEDIUMMsa-24-0002: forum search accepted random parameters in its urlEPSS 0.6%CVE-2021-36397MEDIUMIn Moodle, insufficient capability checks meant message deletions were not limited to the current user.EPSS 0.6%CVE-2025-67847HIGHMoodle: moodle: remote code execution via insufficient restore input validationEPSS 0.6%CVE-2024-25981MEDIUMMsa-24-0004: forum export did not respect activity group settingsEPSS 0.6%CVE-2022-40313HIGHRecursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to loadEPSS 0.6%CVE-2026-26045HIGHMoodle: moodle: improper validation in file restore functionality leading to remote code executionEPSS 0.6%CVE-2020-1692HIGHMoodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.EPSS 0.6%CVE-2022-0985Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary mEPSS 0.6%CVE-2022-0333A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageenEPSS 0.6%CVE-2025-26533HIGHSQL injection risk in course search module list filterEPSS 0.6%