Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Chamilo Lms HIGH 7.2
CVE-2026-33715

Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without a…

Mitigation only
Fix from $1,950 2026-04-14
Chamilo Lms HIGH 7.2
CVE-2026-33714

Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint…

Mitigation only
Fix from $1,950 2026-04-14
Chamilo Lms MEDIUM 6.5
CVE-2026-33703

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/per…

Mitigation only
Fix from $1,600 2026-04-10
Chamilo Lms MEDIUM 5.5
CVE-2025-69581

An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout …

No fix yet
Fix from $1,600 2026-01-16
Chamilo Lms MEDIUM 5.4
CVE-2024-51142

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.ph…

No fix yet
Fix from $1,600 2024-11-15
Chamilo Lms MEDIUM 5.4
CVE-2023-31806

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My P…

Mitigation only
Fix from $1,600 2023-05-09
Chamilo Lms MEDIUM 5.4
CVE-2023-31807

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the pers…

Mitigation only
Fix from $1,600 2023-05-09
Chamilo Lms MEDIUM 6.1
CVE-2023-31801

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter.

Mitigation only
Fix from $1,600 2023-05-09
Chamilo Lms MEDIUM 5.4
CVE-2023-31800

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter.

Mitigation only
Fix from $1,600 2023-05-09
Chamilo Lms MEDIUM 5.4
CVE-2023-31802

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url par…

Mitigation only
Fix from $1,600 2023-05-09
Chamilo Lms MEDIUM 5.4
CVE-2023-31804

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameter…

Mitigation only
Fix from $1,600 2023-05-09
Chamilo HIGH 8.8
CVE-2022-42029

Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads'…

Mitigation only
Fix from $1,950 2022-10-17
Chamilo HIGH 8.8
CVE-2022-40407

A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.

No fix yet
Fix from $1,950 2022-09-29
Chamilo MEDIUM 6.1
CVE-2013-0739

Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script.

Mitigation only
Fix from $1,600 2020-01-30
Chamilo MEDIUM 6.1
CVE-2013-0738

Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php.

Mitigation only
Fix from $1,600 2020-01-30
Chamilo Lms CRITICAL 9.8
CVE-2019-13082

Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive befor…

No fix yet
Fix from $2,300 2019-06-30