Vulnerability index

Browse CVEs

127 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-50188 Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from… Chamilo Lms 1.11.30+ Fix from $1,9502026-03-02 HIGH 7.2 CVE-2025-50191 Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFile with the /main/exercise/ho… Chamilo Lms 1.11.30+ Fix from $1,9502026-03-02 HIGH 7.2 CVE-2024-47886 Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) … Chamilo Lms 1.11.26+ Fix from $1,9502026-03-02 MEDIUM 5.3 CVE-2024-50337 Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, … Chamilo Lms 1.11.28+ Fix from $1,6002026-03-02 MEDIUM 5.4 CVE-2026-1106 A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Control… Chamilo Lms 2.0.0+ Fix from $1,6002026-01-18 MEDIUM 5.5 CVE-2025-69581 An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout … Chamilo Lms No fix yet Fix from $1,6002026-01-16 MEDIUM 5.4 CVE-2024-51142 Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.ph… Chamilo Lms No fix yet Fix from $1,6002024-11-15 HIGH 8.8 CVE-2024-30616 Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, p… Chamilo Lms Patch available Fix from $1,9502024-11-04 HIGH 7.5 CVE-2024-30619 Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number… Chamilo Lms Patch available Fix from $1,9502024-11-04 MEDIUM 6.1 CVE-2024-30618 A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by… Chamilo Lms Patch available Fix from $1,6002024-11-04 MEDIUM 5.4 CVE-2024-30617 A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a… Chamilo Lms Patch available Fix from $1,6002024-11-04 HIGH 7.1 CVE-2024-27524 Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename para… Chamilo Lms Patch available Fix from $1,9502024-11-01 HIGH 8.8 CVE-2023-4226 Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remo… Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-4224 Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain r… Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-4225 Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain … Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-4222 Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtai… Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-4223 Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain … Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 HIGH 8.8 CVE-2023-4221 Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain… Chamilo Lms after 1.11.24 Fix from $1,9502023-11-28 MEDIUM 6.1 CVE-2023-4220EPSS 76% Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows… Chamilo Lms after 1.11.24 Fix from $1,6002023-11-28 CRITICAL 9.8 CVE-2023-3533 Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attac… Chamilo after 1.11.20 Fix from $2,3002023-11-28 CRITICAL 9.8 CVE-2023-3545 Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated atta… Chamilo after 1.11.20 Fix from $2,3002023-11-28 CRITICAL 9.8 CVE-2023-3368EPSS 69% Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code… Chamilo 1.11.20+ Fix from $2,3002023-11-28 CRITICAL 9.8 CVE-2023-34960EPSS 99% A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via … Chamilo after 1.11.18 Fix from $2,3002023-08-01 CRITICAL 9.8 CVE-2023-34944 An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary co… Chamilo Lms after 1.11.18 Fix from $2,3002023-06-13 HIGH 8.1 CVE-2023-34962 Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes. Chamilo Lms after 1.11.18 Fix from $1,9502023-06-08 MEDIUM 6.1 CVE-2023-34961 Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field. Chamilo Lms after 1.11.18 Fix from $1,6002023-06-08 MEDIUM 5.3 CVE-2023-34959 An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services ru… Chamilo Lms after 1.11.18 Fix from $1,6002023-06-08 MEDIUM 5.4 CVE-2023-31806 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My P… Chamilo Lms Mitigation only Fix from $1,6002023-05-09 MEDIUM 5.4 CVE-2023-31807 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the pers… Chamilo Lms Mitigation only Fix from $1,6002023-05-09 MEDIUM 6.1 CVE-2023-31801 Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter. Chamilo Lms Mitigation only Fix from $1,6002023-05-09