CVE-2025-66447
- EPSS 0.03%
- Veröffentlicht 10.04.2026 17:22:32
- Zuletzt bearbeitet 17.04.2026 22:03:27
Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through the use of the redirect parameter to /login. This vulnerability is fixed in 2.0-beta.2.
CVE-2026-30882
- EPSS 0.01%
- Veröffentlicht 16.03.2026 19:21:15
- Zuletzt bearbeitet 17.03.2026 18:52:21
Chamilo LMS is a learning management system. Chamilo LMS version 1.11.34 and prior contains a Reflected Cross-Site Scripting (XSS) vulnerability in the session category listing page. The keyword parameter from $_REQUEST is echoed directly into an HTM...
CVE-2026-30881
- EPSS 0.03%
- Veröffentlicht 16.03.2026 19:19:59
- Zuletzt bearbeitet 17.03.2026 18:52:41
Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the statistics AJAX endpoint. The parameters date_start and date_end from $_REQUEST are embedded directly into a raw SQL string without p...
CVE-2026-30876
- EPSS 0.04%
- Veröffentlicht 16.03.2026 19:18:41
- Zuletzt bearbeitet 17.03.2026 18:53:03
Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with valid/invalid username. This issue has been patched in version 1.11.36.
CVE-2026-30875
- EPSS 0.17%
- Veröffentlicht 16.03.2026 19:16:37
- Zuletzt bearbeitet 17.03.2026 18:53:29
Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated users with Teacher role to achieve Remote Code Execution (RCE). The H5P package validation on...
CVE-2026-28430
- EPSS 0.11%
- Veröffentlicht 16.03.2026 19:13:58
- Zuletzt bearbeitet 17.03.2026 18:53:49
Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQL commands via the custom_dates parameter. By chaining this with a pre...
CVE-2026-29041
- EPSS 0.16%
- Veröffentlicht 06.03.2026 03:32:37
- Zuletzt bearbeitet 09.03.2026 20:20:58
Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability caused by improper validation of uploaded files. The application relies solely on MIME-type verificatio...
CVE-2025-59544
- EPSS 0.04%
- Veröffentlicht 06.03.2026 03:32:20
- Zuletzt bearbeitet 09.03.2026 17:32:34
Chamilo is a learning management system. Prior to version 1.11.34, the functionality for the user to update the category does not implement authorization checks for the "category_id" parameter which allows users to update the category of any user by ...
- EPSS 0.05%
- Veröffentlicht 06.03.2026 03:32:06
- Zuletzt bearbeitet 09.03.2026 17:31:32
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course description field, an attacker with a low-privileged account (e.g., train...
- EPSS 0.05%
- Veröffentlicht 06.03.2026 03:30:04
- Zuletzt bearbeitet 09.03.2026 17:31:21
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course learning path Settings field, an attacker with a low-privileged account (...