CVE-2025-50196
- EPSS 2.75%
- Veröffentlicht 02.03.2026 15:17:53
- Zuletzt bearbeitet 03.03.2026 18:44:16
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinstance.php via the POST main_database parameter. This issue has been patched in version 1.11.30.
CVE-2025-50195
- EPSS 2.66%
- Veröffentlicht 02.03.2026 15:16:59
- Zuletzt bearbeitet 03.03.2026 18:43:56
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.controller.php. This issue has been patched in version 1.11.30.
CVE-2025-50194
- EPSS 2.6%
- Veröffentlicht 02.03.2026 15:16:22
- Zuletzt bearbeitet 03.03.2026 18:43:29
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang.php. This issue has been patched in version 1.11.30.
CVE-2025-50193
- EPSS 2.6%
- Veröffentlicht 02.03.2026 15:16:02
- Zuletzt bearbeitet 03.03.2026 18:43:16
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST to_main_database parameter. This issue has been patched in version 1.11.30.
CVE-2025-50192
- EPSS 0.59%
- Veröffentlicht 02.03.2026 14:54:06
- Zuletzt bearbeitet 03.03.2026 19:13:20
Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30.
CVE-2025-50191
- EPSS 0.54%
- Veröffentlicht 02.03.2026 14:53:36
- Zuletzt bearbeitet 03.03.2026 19:13:46
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php script. This issue has been patched in version 1.11.30.
CVE-2025-50190
- EPSS 0.59%
- Veröffentlicht 02.03.2026 14:53:15
- Zuletzt bearbeitet 03.03.2026 19:14:03
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This issue has been patched in version 1.11.30.
CVE-2025-50189
- EPSS 0.73%
- Veröffentlicht 02.03.2026 14:49:09
- Zuletzt bearbeitet 03.03.2026 19:13:01
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST resource[document][SQL_INJECTION_HERE] and POST login parameters found in /main/coursecopy/...
CVE-2025-50188
- EPSS 0.71%
- Veröffentlicht 02.03.2026 14:47:03
- Zuletzt bearbeitet 03.03.2026 19:12:46
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the GET value parameter with the following scripts: /plugin/vchamilo/views/syncparams.php and /plugi...
CVE-2025-52482
- EPSS 0.37%
- Veröffentlicht 02.03.2026 14:39:50
- Zuletzt bearbeitet 03.03.2026 19:13:35
Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has bee...