Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
moodle moodle 2.8.5 vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2015-3177
Moodle 2.8.x prior to 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.
Moodle Moodle 2.8.0
Moodle Moodle 2.8.3
Moodle Moodle 2.8.4
Moodle Moodle 2.8.5
Moodle Moodle 2.8.1
Moodle Moodle 2.8.2
7.1
CVSSv2
CVE-2015-5332
Atto in Moodle 2.8.x prior to 2.8.9 and 2.9.x prior to 2.9.3 allows remote malicious users to cause a denial of service (disk consumption) by leveraging the guest role and entering drafts with the editor-autosave feature.
Moodle Moodle 2.8.3
Moodle Moodle 2.8.2
Moodle Moodle 2.8.1
Moodle Moodle 2.8.0
Moodle Moodle 2.9.2
Moodle Moodle 2.9.1
Moodle Moodle 2.9.0
Moodle Moodle 2.8.8
Moodle Moodle 2.8.6
Moodle Moodle 2.8.4
Moodle Moodle 2.8.7
Moodle Moodle 2.8.5
4
CVSSv2
CVE-2016-2155
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x prior to 2.8.11, 2.9.x prior to 2.9.5, and 3.0.x prior to 3.0.3 does not consider the moodle/grade:manage capability, which allows remote authenticated users to modify "Exclude grade" settings b...
Moodle Moodle 3.0.2
Moodle Moodle 3.0.1
Moodle Moodle 2.8.9
Moodle Moodle 2.8.8
Moodle Moodle 2.8.1
Moodle Moodle 2.8.0
Moodle Moodle 2.9.1
Moodle Moodle 2.9.0
Moodle Moodle 2.8.10
Moodle Moodle 2.8.3
Moodle Moodle 2.8.2
Moodle Moodle 2.9.3
Moodle Moodle 2.9.2
Moodle Moodle 2.8.5
Moodle Moodle 2.8.4
Moodle Moodle 3.0.0
Moodle Moodle 2.9.4
Moodle Moodle 2.8.7
Moodle Moodle 2.8.6
4
CVSSv2
CVE-2016-2154
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x prior to 2.8.11, 2.9.x prior to 2.9.5, and 3.0.x prior to 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to discover hidden course names by subscribing to ...
Moodle Moodle 2.9.3
Moodle Moodle 2.9.2
Moodle Moodle 2.8.6
Moodle Moodle 2.8.5
Moodle Moodle 2.8.4
Moodle Moodle 3.0.0
Moodle Moodle 2.9.4
Moodle Moodle 2.8.8
Moodle Moodle 2.8.7
Moodle Moodle 3.0.2
Moodle Moodle 3.0.1
Moodle Moodle 2.8.10
Moodle Moodle 2.8.9
Moodle Moodle 2.8.1
Moodle Moodle 2.8.0
Moodle Moodle 2.9.1
Moodle Moodle 2.9.0
Moodle Moodle 2.8.3
Moodle Moodle 2.8.2
4.3
CVSSv2
CVE-2016-0725
Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x prior to 2.8.10, 2.9.x prior to 2.9.4, and 3.0.x prior to 3.0.2 allows remote malicious users to inject arbitrary web script or HTML via a crafted ...
Fedoraproject Fedora 23
Fedoraproject Fedora 22
Moodle Moodle 3.0.1
Moodle Moodle 3.0.0
Moodle Moodle 2.8.6
Moodle Moodle 2.8.5
Moodle Moodle 2.9.3
Moodle Moodle 2.9.2
Moodle Moodle 2.9.1
Moodle Moodle 2.8.4
Moodle Moodle 2.8.3
Moodle Moodle 2.9.0
Moodle Moodle 2.8.9
Moodle Moodle 2.8.2
Moodle Moodle 2.8.1
Moodle Moodle 2.8.8
Moodle Moodle 2.8.7
Moodle Moodle 2.8.0
3.5
CVSSv2
CVE-2015-5269
Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2 allows remote authenticated users to inject arbitrary web script or HTML via a modified grouping description.
Moodle Moodle 2.9.1
Moodle Moodle 2.9.0
Moodle Moodle 2.8.7
Moodle Moodle 2.8.0
Moodle Moodle 2.7.9
Moodle Moodle 2.7.2
Moodle Moodle 2.7.1
Moodle Moodle 2.8.4
Moodle Moodle 2.8.3
Moodle Moodle 2.7.6
Moodle Moodle 2.7.5
Moodle Moodle 2.8.2
Moodle Moodle 2.8.1
Moodle Moodle 2.7.4
Moodle Moodle 2.7.3
Moodle Moodle 2.8.6
Moodle Moodle 2.8.5
Moodle Moodle 2.7.8
Moodle Moodle 2.7.7
Moodle Moodle 2.7.0
Moodle Moodle
5.5
CVSSv2
CVE-2015-5264
The lesson module in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter additional answer attempts by leveraging the student role.
Moodle Moodle 2.8.6
Moodle Moodle 2.8.5
Moodle Moodle 2.7.7
Moodle Moodle 2.7.6
Moodle Moodle
Moodle Moodle 2.9.1
Moodle Moodle 2.8.2
Moodle Moodle 2.8.1
Moodle Moodle 2.7.3
Moodle Moodle 2.7.2
Moodle Moodle 2.9.0
Moodle Moodle 2.8.7
Moodle Moodle 2.8.0
Moodle Moodle 2.7.9
Moodle Moodle 2.7.8
Moodle Moodle 2.7.1
Moodle Moodle 2.7.0
Moodle Moodle 2.8.4
Moodle Moodle 2.8.3
Moodle Moodle 2.7.5
Moodle Moodle 2.7.4
4
CVSSv2
CVE-2015-5265
The wiki component in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, which allows remote authenticated users to delete arbitrary fil...
Moodle Moodle 2.8.4
Moodle Moodle 2.8.3
Moodle Moodle 2.7.5
Moodle Moodle 2.7.4
Moodle Moodle 2.9.0
Moodle Moodle 2.8.7
Moodle Moodle 2.8.0
Moodle Moodle 2.7.9
Moodle Moodle 2.7.8
Moodle Moodle 2.7.1
Moodle Moodle 2.7.0
Moodle Moodle 2.8.6
Moodle Moodle 2.8.5
Moodle Moodle 2.7.7
Moodle Moodle 2.7.6
Moodle Moodle
Moodle Moodle 2.9.1
Moodle Moodle 2.8.2
Moodle Moodle 2.8.1
Moodle Moodle 2.7.3
Moodle Moodle 2.7.2
4
CVSSv2
CVE-2015-5268
The rating component in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.10, 2.8.x prior to 2.8.8, and 2.9.x prior to 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to obtain sensitive information by reading a rating value.
Moodle Moodle 2.8.3
Moodle Moodle 2.8.2
Moodle Moodle 2.7.5
Moodle Moodle 2.7.4
Moodle Moodle 2.8.7
Moodle Moodle 2.8.6
Moodle Moodle 2.7.9
Moodle Moodle 2.7.8
Moodle Moodle 2.7.1
Moodle Moodle 2.7.0
Moodle Moodle 2.8.5
Moodle Moodle 2.8.4
Moodle Moodle 2.7.7
Moodle Moodle 2.7.6
Moodle Moodle
Moodle Moodle 2.9.1
Moodle Moodle 2.9.0
Moodle Moodle 2.8.1
Moodle Moodle 2.8.0
Moodle Moodle 2.7.3
Moodle Moodle 2.7.2
4.3
CVSSv2
CVE-2015-3275
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle up to and including 2.6.11, 2.7.x prior to 2.7.9, 2.8.x prior to 2.8.7, and 2.9.x prior to 2.9.1 allow remote malicious users to inject arbitrary web script or HTML via a crafted organization name t...
Moodle Moodle 2.9.0
Moodle Moodle 2.8.7
Moodle Moodle 2.8.0
Moodle Moodle 2.7.9
Moodle Moodle 2.7.8
Moodle Moodle 2.7.1
Moodle Moodle 2.7.0
Moodle Moodle 2.8.4
Moodle Moodle 2.8.3
Moodle Moodle 2.7.5
Moodle Moodle 2.7.4
Moodle Moodle 2.9.1
Moodle Moodle 2.8.2
Moodle Moodle 2.8.1
Moodle Moodle 2.7.3
Moodle Moodle 2.7.2
Moodle Moodle 2.8.6
Moodle Moodle 2.8.5
Moodle Moodle 2.7.7
Moodle Moodle 2.7.6
Moodle Moodle
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-35977
CVE-2023-49335
man-in-the-middle
CVE-2024-4947
CVE-2024-31714
memory leak
SQL
CVE-2024-35994
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »