Vulnerability index

Browse CVEs

127 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chamilo Lms HIGH 8.8
CVE-2026-40291

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in th…

Fix: after 1.11.38
Fix from $1,950 2026-04-14
Chamilo Lms HIGH 8.8
CVE-2026-35196

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/i…

Fix: after 1.11.38
Fix from $1,950 2026-04-14
Chamilo Lms HIGH 7.1
CVE-2026-34602

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecu…

Fix: after 1.11.38
Fix from $1,950 2026-04-14
Chamilo Lms MEDIUM 6.5
CVE-2026-34370

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Ref…

Fix: after 1.11.38
Fix from $1,600 2026-04-14
Chamilo Lms HIGH 8.6
CVE-2026-34160

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin e…

Fix: after 1.11.38
Fix from $1,950 2026-04-14
Chamilo Lms HIGH 7.2
CVE-2026-33715

Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without a…

Mitigation only
Fix from $1,950 2026-04-14
Chamilo Lms MEDIUM 5.4
CVE-2026-34161

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS) vulnerability exists i…

Fix: after 1.11.38
Fix from $1,600 2026-04-14
Chamilo Lms HIGH 7.2
CVE-2026-33714

Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint…

Mitigation only
Fix from $1,950 2026-04-14
Chamilo Lms HIGH 7.5
CVE-2026-33710

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time() + (user_id * 5) - rand(100…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms MEDIUM 6.5
CVE-2026-33708

Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email,…

Fix: 1.11.38+
Fix from $1,600 2026-04-10
Chamilo Lms MEDIUM 6.5
CVE-2026-33736

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can enumerate all platform users an…

Patch available
Fix from $1,600 2026-04-10
Chamilo Lms MEDIUM 6.5
CVE-2026-33737

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With…

Fix: 1.11.38+
Fix from $1,600 2026-04-10
Chamilo Lms CRITICAL 9.8
CVE-2026-33698

Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ director…

Fix: 1.11.38+
Fix from $2,300 2026-04-10
Chamilo Lms CRITICAL 9.8
CVE-2026-33707

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email…

Fix: 1.11.38+
Fix from $2,300 2026-04-10
Chamilo Lms HIGH 8.8
CVE-2026-33704

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on th…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms HIGH 7.1
CVE-2026-33702

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Object Reference (IDOR) vulnera…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms HIGH 7.1
CVE-2026-33706

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify their own status field via the u…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms MEDIUM 6.5
CVE-2026-33703

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/per…

Mitigation only
Fix from $1,600 2026-04-10
Chamilo Lms MEDIUM 5.3
CVE-2026-33705

Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible witho…

Fix: 1.11.38+
Fix from $1,600 2026-04-10
Chamilo Lms HIGH 8.8
CVE-2026-33618

Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() t…

Patch available
Fix from $1,950 2026-04-10
Chamilo Lms HIGH 8.8
CVE-2026-32931

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload …

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms HIGH 7.1
CVE-2026-32894

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebo…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms HIGH 7.1
CVE-2026-32930

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebo…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms MEDIUM 6.5
CVE-2026-33141

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endp…

Fix: after 1.11.38
Fix from $1,600 2026-04-10
Chamilo Lms MEDIUM 6.1
CVE-2026-32932

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the session course edit page allows a…

Fix: 1.11.38+
Fix from $1,600 2026-04-10
Chamilo Lms HIGH 8.8
CVE-2026-31940

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are direct…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms HIGH 8.8
CVE-2026-32892

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file …

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms HIGH 8.3
CVE-2026-31939

Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file fe…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Chamilo Lms MEDIUM 6.5
CVE-2026-31941

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a Server-Side Request Forgery (SSRF) vulnerability…

Fix: 1.11.38+
Fix from $1,600 2026-04-10
Chamilo Lms MEDIUM 5.4
CVE-2026-32893

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting (XSS) vulnerability in the exercise question list …

Patch available
Fix from $1,600 2026-04-10