Vulnerability index

Browse CVEs

127 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chamilo Lms HIGH 7.2
CVE-2025-50188

Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from…

Fix: 1.11.30+
Fix from $1,950 2026-03-02
Chamilo Lms HIGH 7.2
CVE-2025-50191

Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFile with the /main/exercise/ho…

Fix: 1.11.30+
Fix from $1,950 2026-03-02
Chamilo Lms HIGH 7.2
CVE-2024-47886

Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) …

Fix: 1.11.26+
Fix from $1,950 2026-03-02
Chamilo Lms MEDIUM 5.3
CVE-2024-50337

Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, …

Fix: 1.11.28+
Fix from $1,600 2026-03-02
Chamilo Lms MEDIUM 5.4
CVE-2026-1106

A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Control…

Fix: 2.0.0+
Fix from $1,600 2026-01-18
Chamilo Lms MEDIUM 5.5
CVE-2025-69581

An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout …

No fix yet
Fix from $1,600 2026-01-16
Chamilo Lms MEDIUM 5.4
CVE-2024-51142

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.ph…

No fix yet
Fix from $1,600 2024-11-15
Chamilo Lms HIGH 8.8
CVE-2024-30616

Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, p…

Patch available
Fix from $1,950 2024-11-04
Chamilo Lms HIGH 7.5
CVE-2024-30619

Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number…

Patch available
Fix from $1,950 2024-11-04
Chamilo Lms MEDIUM 6.1
CVE-2024-30618

A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by…

Patch available
Fix from $1,600 2024-11-04
Chamilo Lms MEDIUM 5.4
CVE-2024-30617

A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a…

Patch available
Fix from $1,600 2024-11-04
Chamilo Lms HIGH 7.1
CVE-2024-27524

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename para…

Patch available
Fix from $1,950 2024-11-01
Chamilo Lms HIGH 8.8
CVE-2023-4226

Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remo…

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo Lms HIGH 8.8
CVE-2023-4224

Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain r…

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo Lms HIGH 8.8
CVE-2023-4225

Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain …

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo Lms HIGH 8.8
CVE-2023-4222

Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtai…

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo Lms HIGH 8.8
CVE-2023-4223

Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain …

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo Lms HIGH 8.8
CVE-2023-4221

Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain…

Fix: after 1.11.24
Fix from $1,950 2023-11-28
Chamilo Lms MEDIUM 6.1
CVE-2023-4220EPSS 76%

Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows…

Fix: after 1.11.24
Fix from $1,600 2023-11-28
Chamilo CRITICAL 9.8
CVE-2023-3533

Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attac…

Fix: after 1.11.20
Fix from $2,300 2023-11-28
Chamilo CRITICAL 9.8
CVE-2023-3545

Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated atta…

Fix: after 1.11.20
Fix from $2,300 2023-11-28
Chamilo CRITICAL 9.8
CVE-2023-3368EPSS 69%

Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code…

Fix: 1.11.20+
Fix from $2,300 2023-11-28
Chamilo CRITICAL 9.8
CVE-2023-34960EPSS 99%

A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via …

Fix: after 1.11.18
Fix from $2,300 2023-08-01
Chamilo Lms CRITICAL 9.8
CVE-2023-34944

An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary co…

Fix: after 1.11.18
Fix from $2,300 2023-06-13
Chamilo Lms HIGH 8.1
CVE-2023-34962

Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.

Fix: after 1.11.18
Fix from $1,950 2023-06-08
Chamilo Lms MEDIUM 6.1
CVE-2023-34961

Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.

Fix: after 1.11.18
Fix from $1,600 2023-06-08
Chamilo Lms MEDIUM 5.3
CVE-2023-34959

An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services ru…

Fix: after 1.11.18
Fix from $1,600 2023-06-08
Chamilo Lms MEDIUM 5.4
CVE-2023-31806

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My P…

Mitigation only
Fix from $1,600 2023-05-09
Chamilo Lms MEDIUM 5.4
CVE-2023-31807

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the pers…

Mitigation only
Fix from $1,600 2023-05-09
Chamilo Lms MEDIUM 6.1
CVE-2023-31801

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter.

Mitigation only
Fix from $1,600 2023-05-09