chamilo
Enterprise Softwareoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting chamilo.
- CVE-2026-45140Chamilo LMS CStudio upload flow allows unauthenticated remote code execution9.8
- CVE-2026-45143Chamilo LMS: Student-to-admin stored XSS in private messages via v-html9.0
- CVE-2026-82535Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php6.1
- CVE-2026-34239Chamilo Authenticated Remote Code Execution
- CVE-2026-39878Chamilo stored XSS via user registration leads to admin account takeover9.3
- CVE-2026-40291Chamilo LMS has Privilege Escalation via API User Role Modification8.8
- CVE-2026-35196Chamilo LMS has OS Command Injection via export_all_certificates action8.8
- CVE-2026-34602Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses7.1
- CVE-2026-34370Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes6.5
- CVE-2026-34161Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution5.4
- CVE-2026-34160Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services8.6
- CVE-2026-33715Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action7.2
- CVE-2026-33714Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)7.2
- CVE-2026-33737Chamilo LMS has an XML External Entity (XXE) Injection5.3
- CVE-2026-33736Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposure6.5