Search CVE reports


Toggle filters

1 – 10 of 59604 results

Status is adjusted based on your filters.


CVE-2026-102588

Medium priority
Needs evaluation

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102587

Medium priority
Needs evaluation

A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102586

Medium priority
Needs evaluation

A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102585

Medium priority
Needs evaluation

A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102584

Medium priority
Needs evaluation

A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102583

Medium priority
Needs evaluation

A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102582

Medium priority
Needs evaluation

A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102581

Medium priority
Needs evaluation

A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious content into a forum post, which then...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102580

Medium priority
Needs evaluation

A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages

CVE-2026-102579

Medium priority
Needs evaluation

A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other students enrolled in the same course that they should not have permission to...

1 affected package

moodle

Package 16.04 LTS
moodle Needs evaluation
Show less packages