CVE-2025-59541
- EPSS 0.02%
- Veröffentlicht 06.03.2026 03:29:34
- Zuletzt bearbeitet 09.03.2026 17:30:32
Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete projects inside a course without the victim’s consent. The issue arises because sensitive actions such a...
CVE-2025-59540
- EPSS 0.04%
- Veröffentlicht 06.03.2026 03:27:53
- Zuletzt bearbeitet 09.03.2026 17:31:00
Chamilo is a learning management system. Prior to version 1.11.34, a stored XSS vulnerability exists in Chamilo LMS that allows a staff account to execute arbitrary JavaScript in the browser of higher-privileged admin users. The issue arises because ...
- EPSS 0.05%
- Veröffentlicht 06.03.2026 03:27:45
- Zuletzt bearbeitet 09.03.2026 17:30:11
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an attacker to inject arbitrary JavaScript into the platform’s social network and internal messaging featur...
- EPSS 0.06%
- Veröffentlicht 05.03.2026 20:58:27
- Zuletzt bearbeitet 09.03.2026 20:20:00
Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, a low-privilege user can execute arbitrary code in the admin user inbox, allowing takeover of the adm...
CVE-2025-52564
- EPSS 0.04%
- Veröffentlicht 02.03.2026 15:54:42
- Zuletzt bearbeitet 03.03.2026 18:21:24
Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as underlined text, via a crafted URL. This issue has been...
CVE-2025-52998
- EPSS 0.22%
- Veröffentlicht 02.03.2026 15:54:19
- Zuletzt bearbeitet 03.03.2026 18:21:38
Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary classes, as well as fully control their properties, and ...
CVE-2025-50199
- EPSS 0.07%
- Veröffentlicht 02.03.2026 15:50:45
- Zuletzt bearbeitet 03.03.2026 18:47:26
Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in version 1.11.30.
CVE-2025-52563
- EPSS 0.04%
- Veröffentlicht 02.03.2026 15:50:20
- Zuletzt bearbeitet 03.03.2026 18:21:58
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to insufficient sanitization of the page parameter in the session/add_users_to_session.php endpoint. This issue has b...
CVE-2025-52475
- EPSS 0.04%
- Veröffentlicht 02.03.2026 15:49:52
- Zuletzt bearbeitet 03.03.2026 18:22:26
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability in the admin/user_list.php endpoint. The keyword_inactive parameter is not properly sanitized, allowing attackers to inje...
CVE-2025-52476
- EPSS 0.04%
- Veröffentlicht 02.03.2026 15:49:32
- Zuletzt bearbeitet 03.03.2026 18:22:14
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to improper sanitization of the keyword_active parameter in admin/user_list.php. This issue has been patched in versi...