Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.2
CVE-2025-50188
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from…
Chamilo Lms
1.11.30+
HIGH 7.2
CVE-2025-50191
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFile with the /main/exercise/ho…
Chamilo Lms
1.11.30+
HIGH 7.2
CVE-2024-47886
Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) …
Chamilo Lms
1.11.26+
MEDIUM 5.3
CVE-2024-50337
Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, …
Chamilo Lms
1.11.28+
MEDIUM 5.4
CVE-2026-1106
A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Control…
Chamilo Lms
2.0.0+
MEDIUM 5.5
CVE-2025-69581
An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout …
Chamilo Lms
No fix yet
MEDIUM 5.4
CVE-2024-51142
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.ph…
Chamilo Lms
No fix yet
HIGH 8.8
CVE-2024-30616
Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, p…
Chamilo Lms
Patch available
HIGH 7.5
CVE-2024-30619
Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number…
Chamilo Lms
Patch available
MEDIUM 6.1
CVE-2024-30618
A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by…
Chamilo Lms
Patch available
MEDIUM 5.4
CVE-2024-30617
A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a…
Chamilo Lms
Patch available
HIGH 7.1
CVE-2024-27524
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename para…
Chamilo Lms
Patch available
HIGH 8.8
CVE-2023-4226
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remo…
Chamilo Lms
after 1.11.24
HIGH 8.8
CVE-2023-4224
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain r…
Chamilo Lms
after 1.11.24
HIGH 8.8
CVE-2023-4225
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain …
Chamilo Lms
after 1.11.24
HIGH 8.8
CVE-2023-4222
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtai…
Chamilo Lms
after 1.11.24
HIGH 8.8
CVE-2023-4223
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain …
Chamilo Lms
after 1.11.24
HIGH 8.8
CVE-2023-4221
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain…
Chamilo Lms
after 1.11.24
MEDIUM 6.1
CVE-2023-4220EPSS 76%
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows…
Chamilo Lms
after 1.11.24
CRITICAL 9.8
CVE-2023-3533
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attac…
Chamilo
after 1.11.20
CRITICAL 9.8
CVE-2023-3545
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated atta…
Chamilo
after 1.11.20
CRITICAL 9.8
CVE-2023-3368EPSS 69%
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code…
Chamilo
1.11.20+
CRITICAL 9.8
CVE-2023-34960EPSS 99%
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via …
Chamilo
after 1.11.18
CRITICAL 9.8
CVE-2023-34944
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary co…
Chamilo Lms
after 1.11.18
HIGH 8.1
CVE-2023-34962
Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.
Chamilo Lms
after 1.11.18
MEDIUM 6.1
CVE-2023-34961
Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.
Chamilo Lms
after 1.11.18
MEDIUM 5.3
CVE-2023-34959
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services ru…
Chamilo Lms
after 1.11.18
MEDIUM 5.4
CVE-2023-31806
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My P…
Chamilo Lms
Mitigation only
MEDIUM 5.4
CVE-2023-31807
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the pers…
Chamilo Lms
Mitigation only
MEDIUM 6.1
CVE-2023-31801
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter.
Chamilo Lms
Mitigation only