CVE-2022-0332: Moodle
Critical severity, CVSS 9.8. EPSS: 44.9% chance of exploitation in the next 30 days.
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.
Affected products
- Moodle Moodle: from 3.11.0, before 3.11.5 (fixed in 3.11.5)
Published 2022-01-25. Last modified 2026-06-17.