Technology · Packagist
moodle/moodle (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 71 vulnerabilities in moodle/moodle (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-62393, was published on 23 October 2025.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About moodle/moodle (Packagist)
Open-source learning management system for creating and managing online courses and educational content.
Latest moodle/moodle (Packagist) vulnerabilities
- CVE-2025-62393: Moodle course access permissions are not properly checked in course_output_fragment_course_overviewlowCVSS 3.1EPSS 0.3%
- CVE-2025-53021: Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameterlowCVSS 3.1EPSS 0.3%
- CVE-2025-32044: Moodle allows unauthenticated REST API user data exposurelowCVSS 3.1EPSS 0.5%
- CVE-2025-3628: Moodle reveals student identities through assignment submissions search on anonymous submissionslowCVSS 3.1EPSS 0.3%
- CVE-2024-48899: Moodle IDOR when accessing list of course badgeslowCVSS 3.1EPSS 0.3%
- CVE-2024-48900: Moodle IDOR when accessing list of badge recipientsmediumCVSS 4EPSS 0.4%
- CVE-2024-43430: Moodle has insufficient access controllowCVSS 3.1EPSS 0.3%
- CVE-2024-34009: Moodle ReCAPTCHA can be bypassed on the login pagelowCVSS 3.1EPSS 0.4%
- CVE-2024-34007: Moodle Logout CSRF in admin/tool/mfa/auth.phpinfoEPSS 0.4%
- CVE-2024-33999: Moodle Improper Input ValidationinfoEPSS 0.5%
- CVE-2024-28593: Cross-site Scripting in Moodle ChatlowCVSS 3.1EPSS 0.5%
- CVE-2024-29374: Cross site scripting in moodlelowCVSS 3.1EPSS 0.5%
- CVE-2024-1439: Moodle Improper Access Control vulnerabilitylowCVSS 3.1EPSS 0.3%
- CVE-2023-5548: Moodle Acceptance of Extraneous Untrusted Data With Trusted Data vulnerabilitylowCVSS 3.1EPSS 0.3%
- CVE-2023-5544: Moodle Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 0.5%
- CVE-2023-5547: Moodle Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 0.5%
- CVE-2023-5549: Moodle Improper Access Control vulnerabilitylowCVSS 3.1EPSS 0.6%
- CVE-2023-5545: Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerabilitylowCVSS 3.1EPSS 0.5%
- CVE-2023-5542: Moodle Improper Access Control vulnerabilitylowCVSS 3.1EPSS 0.4%
- CVE-2023-5539: Moodle Code Injection vulnerabilitylowCVSS 3.1EPSS 1.9%
- CVE-2023-5541: Moodle Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 0.5%
- CVE-2023-5546: Moodle Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 1.2%
- CVE-2023-5540: Moodle Code Injection vulnerabilitylowCVSS 3.1EPSS 1.9%
- CVE-2021-27131: Moodle vulnerable to stored Cross-site ScriptinglowCVSS 3.1EPSS 0.7%
- CVE-2023-30944: Moodle SQL Injection vulnerabilitylowCVSS 3.1EPSS 1.1%
Most severe moodle/moodle (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2016-5012: Moodle improper authorization in glossary searchmediumCVSS 5.3EPSS 1.1%
- CVE-2011-4284: Moodle allows remote attackers to obtain sensitive information from myprofile block by visiting user-context pagemediumCVSS 4EPSS 2.1%
- CVE-2011-4287: Moodle does not force password changes for autosubscribed usersmediumCVSS 4EPSS 2.1%
- CVE-2011-4292: Moodle allows remote authenticated users to cause a denial of service (invalid database records)mediumCVSS 4EPSS 2.0%
- CVE-2011-4291: Moodle allows remote authenticated users to cause a denial of service (invalid database records)mediumCVSS 4EPSS 1.9%
- CVE-2011-4282: Moodle vulnerable to Cross-site ScriptingmediumCVSS 4EPSS 1.8%
- CVE-2010-1613: Moodle Session Fixation vulnerabilitymediumCVSS 4EPSS 1.8%
- CVE-2011-4289: Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course membersmediumCVSS 4EPSS 1.7%
- CVE-2011-4279: Moodle does not use the forceloginforprofiles setting for course-profiles access controlmediumCVSS 4EPSS 1.4%
- CVE-2011-4281: Moodle vulnerable to Cross-Site Request ForgerymediumCVSS 4EPSS 1.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/moodle-moodle.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "moodle/moodle (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/moodle-moodle, 28 September 2026.