5.3

CVSS4.0

CVE-2026-28357 - NocoDB: Stored Cross-Site Scripting via Formula Cell

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, a stored XSS vulnerability exists in the Formula virtual cell. Formula results containing URI::() patterns are rendered via v-html without sanitization, allowing injected HTML to execute. This issue has been patche…

πŸ“… Published: March 2, 2026, 4:16 p.m. πŸ”„ Last Modified: March 2, 2026, 4:16 p.m.

5.3

CVSS3.1

CVE-2026-23865 -

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

πŸ“… Published: March 2, 2026, 4:09 p.m. πŸ”„ Last Modified: March 2, 2026, 4:09 p.m.

6.9

CVSS4.0

CVE-2025-52564 - Chamilo: HTML injection via open parameter

Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as underlined text, via a crafted URL. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 3:54 p.m. πŸ”„ Last Modified: March 2, 2026, 3:54 p.m.

7

CVSS4.0

CVE-2025-52998 - Chamilo: PHAR deserialization bypass

Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary classes, as well as fully control their properties, and thus modify the logic of the web application's op…

πŸ“… Published: March 2, 2026, 3:54 p.m. πŸ”„ Last Modified: March 2, 2026, 3:54 p.m.

7.7

CVSS4.0

CVE-2025-50199 - Chamilo: Blind Server-Side Request Forgery (Unauth Blind SSRF)

Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 3:50 p.m. πŸ”„ Last Modified: March 2, 2026, 3:50 p.m.

5.1

CVSS4.0

CVE-2025-52563 - Chamilo: Reflected XSS via page parameter

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to insufficient sanitization of the page parameter in the session/add_users_to_session.php endpoint. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 3:50 p.m. πŸ”„ Last Modified: March 2, 2026, 3:50 p.m.

5.1

CVSS4.0

CVE-2025-52475 - Chamilo: Reflected XSS via keyword_inactive parameter

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability in the admin/user_list.php endpoint. The keyword_inactive parameter is not properly sanitized, allowing attackers to inject malicious JavaScript through a crafted URL. Th…

πŸ“… Published: March 2, 2026, 3:49 p.m. πŸ”„ Last Modified: March 2, 2026, 3:49 p.m.

5.1

CVSS4.0

CVE-2025-52476 - Chamilo: Reflected XSS via keyword_active parameter

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to improper sanitization of the keyword_active parameter in admin/user_list.php. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 3:49 p.m. πŸ”„ Last Modified: March 2, 2026, 3:49 p.m.

4.8

CVSS3.1

CVE-2025-52470 - Chamilo: Stored Cross-Site Scripting (XSS) via Session Category Name

Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists in the session_category_add.php script. The vulnerability is caused by improper sanitization of the Category Name field, allowing privileged users to inject persistent JavaScr…

πŸ“… Published: March 2, 2026, 3:48 p.m. πŸ”„ Last Modified: March 2, 2026, 3:48 p.m.

7.1

CVSS3.1

CVE-2025-52469 - Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypass

Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated user to forcibly add any user as a friend by directly calling the AJAX endpoint. The attacker can bypass the normal flow…

πŸ“… Published: March 2, 2026, 3:48 p.m. πŸ”„ Last Modified: March 2, 2026, 3:48 p.m.
Total resulsts: 335430
Page 11 of 33,543
Β« previous page Β» next page
Filters