7.1

CVSS3.1

CVE-2026-33706 - Chamilo LMS has a REST API Self-Privilege Escalation (Student → Teacher)

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify their own status field via the update_user_from_username endpoint. A student (status=5) can change their status to Teacher/CourseManager (status=1), gaining course creation and manag…

📅 Published: April 10, 2026, 6:51 p.m. 🔄 Last Modified: April 10, 2026, 7:16 p.m.

5.3

CVSS3.1

CVE-2026-33705 - Chamilo LMS has unauthenticated access to Twig template source files exposes application logic

Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET requests. These templates expose internal application logic, variable names, AJAX endpoint URLs, and admin panel struct…

📅 Published: April 10, 2026, 6:32 p.m. 🔄 Last Modified: April 10, 2026, 7:16 p.m.

7.1

CVSS3.1

CVE-2026-33704 - Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on the server via the BigUpload endpoint. The key parameter controls the filename and the raw POST body becomes the file content. While .php extensions are…

📅 Published: April 10, 2026, 6:30 p.m. 🔄 Last Modified: April 10, 2026, 7:16 p.m.

7.1

CVSS4.0

CVE-2026-33703 - Chamilo LMS Critical IDOR: Any Authenticated User Can Extract All Users’ Personal Data and API Toke…

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/personal-data/{userId} endpoint allows any authenticated user to access full personal data and API tokens of arbitrary users by modifying the userId para…

📅 Published: April 10, 2026, 6:23 p.m. 🔄 Last Modified: April 10, 2026, 7:16 p.m.

6

CVSS4.0

CVE-2026-3446 - Base64 decoding stops at first padded quad by default

When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "vali…

📅 Published: April 10, 2026, 6:17 p.m. 🔄 Last Modified: April 10, 2026, 7:16 p.m.

7.1

CVSS3.1

CVE-2026-33702 - Chamilo LMS has an Insecure Direct Object Reference (IDOR)

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Object Reference (IDOR) vulnerability in the Learning Path progress saving endpoint. The file lp_ajax_save_item.php accepts a uid (user ID) parameter directly from $_REQUEST and use…

📅 Published: April 10, 2026, 6:15 p.m. 🔄 Last Modified: April 10, 2026, 7:16 p.m.

9.3

CVSS4.0

CVE-2026-33698 - Chamilo LMS affected by unauthenticated RCE in main/install folder

Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals wi…

📅 Published: April 10, 2026, 6:14 p.m. 🔄 Last Modified: April 10, 2026, 7:16 p.m.

8.8

CVSS3.1

CVE-2026-33618 - Chamilo LMS Affected by Remote Code Execution via eval() in Platform Settings

Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() to parse platform settings from the database. An attacker with admin access (obtainable via Advisory 1) can inject arbitrary PHP code into the settings…

📅 Published: April 10, 2026, 6:10 p.m. 🔄 Last Modified: April 10, 2026, 7:16 p.m.

6.5

CVSS3.1

CVE-2026-33141 - Chamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Data

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endpoint allows any authenticated user (including low-privilege students with ROLE_USER) to read any other user's learning progress, certificates, and gra…

📅 Published: April 10, 2026, 6:01 p.m. 🔄 Last Modified: April 10, 2026, 6:16 p.m.

9.1

CVSS3.1

CVE-2026-32892 - OS Command Injection in Chamilo LMS 1.11.36

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapesh…

📅 Published: April 10, 2026, 5:56 p.m. 🔄 Last Modified: April 10, 2026, 6:16 p.m.
Total resulsts: 343948
Page 10 of 34,395
« previous page » next page
Filters