8.8
CVE-2025-50190 - Chamilo: Error-based SQL Injection via GET openid.assoc_handle with the /index.php script
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This issue has been patched in version 1.11.30.
0.0
CVE-2026-0995 -
An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to ensure the completion of memory accesses related to SME.
7.2
CVE-2025-50189 - Chamilo: Error-based SQL Injection
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST resource[document][SQL_INJECTION_HERE] and POST login parameters found in /main/coursecopy/copy_course_session_selected.php, which allows anβ¦
7
CVE-2025-50188 - Error-based SQL Injection in Chamilo LMS
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the GET value parameter with the following scripts: /plugin/vchamilo/views/syncparams.php and /plugin/vchamilo/ajax/service.php, which allows an attaβ¦
8.3
CVE-2025-52482 - Chamilo: Stored XSS in glossary function via /main/glossary/index.php trigger in /main/tracking/couβ¦
Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.
9.8
CVE-2025-50187 - Chamilo: Evaluation of untrusted user input leads to Remote Code Execution
Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has been patched in version 1.11.28.
4.8
CVE-2025-50186 - Chamilo: Stored XSS via Malicious CSV Filename in user_import.php
Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists due to insufficient sanitization of CSV filenames. An attacker can upload a maliciously named CSV file (e.g., <img src=q onerror=prompt(8)>.csv) that leads to JavaScript execuβ¦
5.3
CVE-2024-50337 - Chamilo: Potential unauthenticated blind SSRF via openid function
Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, which results in unauthenticated blind SSRF. This issue has been patched in version 1.11.28.
8.7
CVE-2024-47886 - Chamilo: Post-Auth Remote Code Execution
Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing multiple supported features from the virtualization plugin vchamilo, the vulnerability allows an adminiβ¦
10
CVE-2026-23600 -
A remote authentication bypass vulnerabilityΒ exists in HPE AutoPass License Server (APLS).