CVEs we hold for Chamilo-lms
Records whose assigning authority named Chamilo-lms as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-45140Chamilo LMS CStudio upload flow allows unauthenticated remote code executionchamilo-lms
CVE-2026-34602Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courseschamilo-lms
CVE-2026-34370Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private noteschamilo-lms
CVE-2026-34161Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Executionchamilo-lms
CVE-2026-34160Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata…chamilo-lms
CVE-2026-33736Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposurechamilo-lms
CVE-2026-33715Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer actionchamilo-lms
CVE-2026-33714Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)chamilo-lms
CVE-2026-33707Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lmschamilo-lms
CVE-2026-33705Chamilo LMS has unauthenticated access to Twig template source files exposes application logicchamilo-lms
CVE-2026-33704Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpointchamilo-lms
CVE-2026-33703Chamilo LMS Critical IDOR: Any Authenticated User Can Extract All Users’ Personal Data and API Tokenschamilo-lms
CVE-2026-33618Chamilo LMS Affected by Remote Code Execution via eval() in Platform Settingschamilo-lms
CVE-2026-33141Chamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Datachamilo-lms
CVE-2026-32932Chamilo LMS has an Open Redirect via Unvalidated 'page' Parameter in Session Course Editchamilo-lms
CVE-2026-32931Chamilo LMS has Arbitrary File Upload via MIME-Only Validation in Exercise Sound Upload Leads to RCEchamilo-lms
CVE-2026-32930Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Evaluation Edit Without Ownership Checkchamilo-lms
CVE-2026-32894Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Deletion of Any Student's Grade Resultchamilo-lms
CVE-2026-32893Chamilo LMS has Reflected XSS via Unsanitized http_build_query() in Exercise Question List Paginationchamilo-lms
CVE-2026-28430Chamilo LMS Vulnerable to Unauthenticated SQL Injection in chamiko-lms model.ajax.phpchamilo-lms
CVE-2025-59540Chamilo: Stored Cross-Site Scripting (XSS) in Chamilo LMS Exercise Feedbackchamilo-lms
CVE-2025-55208Chamilo LMS has Stored Cross Site Scripting on Social Networks Uploaded Fileschamilo-lms
CVE-2025-52482Chamilo: Stored XSS in glossary function via /main/glossary/index.php trigger in /main/tracking/course_log_resources.phpchamilo-lms
CVE-2025-52469Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypasschamilo-lms
CVE-2025-50198Chamilo: Deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file…chamilo-lms
CVE-2025-50197Chamilo: OS Command Injection in /main/admin/sub_language_ajax.inc.php via POST new_language parameterchamilo-lms
CVE-2025-50196Chamilo: OS Command Injection in /plugin/vchamilo/views/editinstance.php via POST main_database parameterchamilo-lms
CVE-2025-50195Chamilo: OS Command Injection in /plugin/vchamilo/views/manage.controller.phpchamilo-lms
CVE-2025-50193Chamilo: OS command Injection in /plugin/vchamilo/views/import.php with the POST to_main_database parameterchamilo-lms
CVE-2025-50192Chamilo: Time-based SQL Injection in /main/webservices/registration.soap.phpchamilo-lms
CVE-2025-50191Chamilo: Error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php scriptchamilo-lms
CVE-2025-50190Chamilo: Error-based SQL Injection via GET openid.assoc_handle with the /index.php scriptchamilo-lms
74 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.