CVE-2026-28430
- EPSS 0.33%
- Veröffentlicht 16.03.2026 19:13:58
- Zuletzt bearbeitet 17.03.2026 18:53:49
Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQL commands via the custom_dates parameter. By chaining this with a pre...
CVE-2026-29041
- EPSS 0.73%
- Veröffentlicht 06.03.2026 03:32:37
- Zuletzt bearbeitet 09.03.2026 20:20:58
Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability caused by improper validation of uploaded files. The application relies solely on MIME-type verificatio...
CVE-2025-59544
- EPSS 0.17%
- Veröffentlicht 06.03.2026 03:32:20
- Zuletzt bearbeitet 09.03.2026 17:32:34
Chamilo is a learning management system. Prior to version 1.11.34, the functionality for the user to update the category does not implement authorization checks for the "category_id" parameter which allows users to update the category of any user by ...
- EPSS 0.25%
- Veröffentlicht 06.03.2026 03:32:06
- Zuletzt bearbeitet 09.03.2026 17:31:32
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course description field, an attacker with a low-privileged account (e.g., train...
- EPSS 0.3%
- Veröffentlicht 06.03.2026 03:30:04
- Zuletzt bearbeitet 09.03.2026 17:31:21
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course learning path Settings field, an attacker with a low-privileged account (...
CVE-2025-59541
- EPSS 0.15%
- Veröffentlicht 06.03.2026 03:29:34
- Zuletzt bearbeitet 09.03.2026 17:30:32
Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete projects inside a course without the victim’s consent. The issue arises because sensitive actions such a...
CVE-2025-59540
- EPSS 0.18%
- Veröffentlicht 06.03.2026 03:27:53
- Zuletzt bearbeitet 09.03.2026 17:31:00
Chamilo is a learning management system. Prior to version 1.11.34, a stored XSS vulnerability exists in Chamilo LMS that allows a staff account to execute arbitrary JavaScript in the browser of higher-privileged admin users. The issue arises because ...
- EPSS 0.3%
- Veröffentlicht 06.03.2026 03:27:45
- Zuletzt bearbeitet 09.03.2026 17:30:11
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an attacker to inject arbitrary JavaScript into the platform’s social network and internal messaging featur...
- EPSS 0.31%
- Veröffentlicht 05.03.2026 20:58:27
- Zuletzt bearbeitet 09.03.2026 20:20:00
Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, a low-privilege user can execute arbitrary code in the admin user inbox, allowing takeover of the adm...
CVE-2025-52564
- EPSS 0.19%
- Veröffentlicht 02.03.2026 15:54:42
- Zuletzt bearbeitet 03.03.2026 18:21:24
Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as underlined text, via a crafted URL. This issue has been...