Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2026-33715 Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without a… Chamilo Lms Mitigation only Fix from $1,9502026-04-14 HIGH 7.2 CVE-2026-33714 Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint… Chamilo Lms Mitigation only Fix from $1,9502026-04-14 MEDIUM 6.5 CVE-2026-33703 Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/per… Chamilo Lms Mitigation only Fix from $1,6002026-04-10 MEDIUM 5.5 CVE-2025-69581 An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout … Chamilo Lms No fix yet Fix from $1,6002026-01-16 MEDIUM 5.4 CVE-2024-51142 Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.ph… Chamilo Lms No fix yet Fix from $1,6002024-11-15 MEDIUM 5.4 CVE-2023-31806 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My P… Chamilo Lms Mitigation only Fix from $1,6002023-05-09 MEDIUM 5.4 CVE-2023-31807 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the pers… Chamilo Lms Mitigation only Fix from $1,6002023-05-09 MEDIUM 6.1 CVE-2023-31801 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter. Chamilo Lms Mitigation only Fix from $1,6002023-05-09 MEDIUM 5.4 CVE-2023-31800 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter. Chamilo Lms Mitigation only Fix from $1,6002023-05-09 MEDIUM 5.4 CVE-2023-31802 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url par… Chamilo Lms Mitigation only Fix from $1,6002023-05-09 MEDIUM 5.4 CVE-2023-31804 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameter… Chamilo Lms Mitigation only Fix from $1,6002023-05-09 HIGH 8.8 CVE-2022-42029 Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads'… Chamilo Mitigation only Fix from $1,9502022-10-17 HIGH 8.8 CVE-2022-40407 A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file. Chamilo No fix yet Fix from $1,9502022-09-29 MEDIUM 6.1 CVE-2013-0739 Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script. Chamilo Mitigation only Fix from $1,6002020-01-30 MEDIUM 6.1 CVE-2013-0738 Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php. Chamilo Mitigation only Fix from $1,6002020-01-30 CRITICAL 9.8 CVE-2019-13082 Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive befor… Chamilo Lms No fix yet Fix from $2,3002019-06-30