CVE-2022-0332: Moodle

Critical severity, CVSS 9.8. EPSS: 44.9% chance of exploitation in the next 30 days.

A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.

Affected products

  • Moodle Moodle: from 3.11.0, before 3.11.5 (fixed in 3.11.5)

Published 2022-01-25. Last modified 2026-06-17.