Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

98 advisories

Loading
Moodle XSS Vulnerability Moderate
CVE-2019-3847 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle Stored HTML in assignment submission comments allowed links to be opened directly Moderate
CVE-2019-3850 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle Secure layout contained an insecure link in Boost theme Moderate
CVE-2019-3851 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle mishandles group-based authorization checks Moderate
CVE-2015-5268 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle cross-site scripting (XSS) vulnerability Moderate
CVE-2015-5269 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle cross-site request forgery (CSRF) vulnerability Moderate
CVE-2015-5335 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle multiple cross-site scripting (XSS) vulnerabilities Moderate
CVE-2015-5336 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle does not properly implement group-based access restrictions Moderate
CVE-2015-5339 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle allows attackers to read SCORM contents Moderate
CVE-2015-5341 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle allows attackers to bypass intended access restrictions Moderate
CVE-2015-5342 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle provides calendar-event data without considering whether an activity is hidden Moderate
CVE-2016-2156 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle allows attackers to discover student e-mail addresses Moderate
CVE-2016-2151 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle allows attackers to modify "Exclude grade" settings Moderate
CVE-2016-2155 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle allows attackers to obtain sensitive category-detail information Moderate
CVE-2016-2158 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle allows attackers to discover hidden course names Moderate
CVE-2016-2154 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle XSS from profile fields from external db Moderate
CVE-2016-2152 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle External function mod_assign_save_submission does not check due dates Moderate
CVE-2016-2159 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle cross-site request forgery (CSRF) vulnerability Moderate
CVE-2015-0218 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle cross-site scripting (XSS) vulnerability Moderate
CVE-2014-0218 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle allows discovery of an author's username Moderate
CVE-2014-3617 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle context freezing Moderate
CVE-2019-3852 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle Improper Access Control Moderate
CVE-2016-3733 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Moodle cross-site scripting (XSS) vulnerabilities Moderate
CVE-2013-7341 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
ProTip! Advisories are also available from the GraphQL API