8.8

CVSS3.1

CVE-2026-35196 - Chamilo LMS has OS Command Injection via export_all_certificates action

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/inc/ajax/gradebook.ajax.php endpoint within the export_all_certificates action, where the course code retrieved from the session variable $_SESSION['_c…

📅 Published: April 14, 2026, 9:33 p.m. 🔄 Last Modified: April 22, 2026, 6:37 p.m.

7.1

CVSS3.1

CVE-2026-34602 - Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into C…

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecure Direct Object Reference (IDOR), allowing an authenticated attacker to modify the user parameter in the request body to enroll any arbitrary user in…

📅 Published: April 14, 2026, 9:29 p.m. 🔄 Last Modified: April 22, 2026, 6:46 p.m.

5.3

CVSS3.1

CVE-2025-15565 - Nexi XPay <= 8.3.0 - Missing Authorization to Unauthenticated Order Status Modification

The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This makes it possible for unauthenticated attackers to mark pending WooCommerce orders as paid/completed.

📅 Published: April 14, 2026, 9:26 p.m. 🔄 Last Modified: April 22, 2026, 8:23 p.m.

6.5

CVSS3.1

CVE-2026-34370 - Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated student to read the private course notes of any other user on the platform by manipulating t…

📅 Published: April 14, 2026, 9:25 p.m. 🔄 Last Modified: April 22, 2026, 6:46 p.m.

7

CVSS4.0

CVE-2026-39907 - Unisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via WCF SOAP

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attackers to trigger SMB connections and leak NTLMv2 machine-accoun…

📅 Published: April 14, 2026, 9:21 p.m. 🔄 Last Modified: April 23, 2026, 2:40 p.m.

7

CVSS4.0

CVE-2026-39906 - Unisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via .NET Remoting

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a Windows UNC path as a target file argument through object-unmarshalling techniques…

📅 Published: April 14, 2026, 9:21 p.m. 🔄 Last Modified: April 23, 2026, 2:38 p.m.

7.8

CVSS3.1

CVE-2026-34631 - InCopy | Out-of-bounds Write (CWE-787)

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

📅 Published: April 14, 2026, 9:14 p.m. 🔄 Last Modified: April 15, 2026, 7:33 p.m.

5.1

CVSS4.0

CVE-2026-34161 - Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary Jav…

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the social post attachment upload functionality, where an authenticated user can upload a malicious HTML file containing JavaScript via the /api/soc…

📅 Published: April 14, 2026, 9:12 p.m. 🔄 Last Modified: April 23, 2026, 2:57 p.m.

8.6

CVSS3.1

CVE-2026-34160 - Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and rea…

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin endpoint at public/plugin/Pens/pens.php is accessible without authentication and accepts a user-controlled package-url parameter that the server fetche…

📅 Published: April 14, 2026, 9:09 p.m. 🔄 Last Modified: April 23, 2026, 2:56 p.m.

7.2

CVSS3.1

CVE-2026-33715 - Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action

Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without authentication on fully installed instances because, unlike other AJAX endpoints, it does not include the global.inc.php file that performs authenticat…

📅 Published: April 14, 2026, 9:05 p.m. 🔄 Last Modified: April 23, 2026, 2:56 p.m.
Total resulsts: 346120
Page 154 of 34,612
« previous page » next page
Filters