In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.
In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.
In Moodle 3.x, course creators are able to change system default settings for courses.
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
In Moodle 3.x, there is Cross-site Scripting in the assignment submission page.
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
In Moodle 3.x, XSS can occur via evidence of prior learning.
In Moodle 2.x and 3.x, text injection can occur in email headers, potentially leading to outbound spam.
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course.
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.
In Moodle 3.x, glossary search displays entries without checking user permissions to view them.
In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.
In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.