6.5

CVSS3.1

CVE-2026-27460 - Tandoor Recipes Affected by Denial of Service via Recipe Import

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import functionality. This vulnerability allows an authenticated user to crash the server or make a significantly d…

πŸ“… Published: April 10, 2026, 7:09 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

5.3

CVSS3.1

CVE-2026-33737 - Chamilo LMS has an XML External Entity (XXE) Injection

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT flag, arbitrary server files can be read. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.

πŸ“… Published: April 10, 2026, 7:05 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

6.5

CVSS3.1

CVE-2026-33736 - Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposure

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can enumerate all platform users and access personal information (email, phone, roles) via GET /api/users, including administrator accounts. This vulnerability is fixed in 2.0.0-RC.3.

πŸ“… Published: April 10, 2026, 7:03 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2026-33710 - Chamilo LMS has Weak REST API Key Generation (Predictable)

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time() + (user_id * 5) - rand(10000, 10000)). The rand(10000, 10000) call always returns exactly 10000 (min == max), making the formula effectively md5(timestamp + user_id*5 - 10000).…

πŸ“… Published: April 10, 2026, 6:59 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

6.5

CVSS3.1

CVE-2026-33708 - Chamilo LMS has REST API PII Exposure via get_user_info_from_username

Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email, first name, last name, user ID, active status) of any user to any authenticated user, including students. There is no authorization check. This vulne…

πŸ“… Published: April 10, 2026, 6:54 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

9.4

CVSS3.1

CVE-2026-33707 - Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victi…

πŸ“… Published: April 10, 2026, 6:52 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.1

CVSS3.1

CVE-2026-33706 - Chamilo LMS has a REST API Self-Privilege Escalation (Student β†’ Teacher)

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify their own status field via the update_user_from_username endpoint. A student (status=5) can change their status to Teacher/CourseManager (status=1), gaining course creation and manag…

πŸ“… Published: April 10, 2026, 6:51 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

5.3

CVSS3.1

CVE-2026-33705 - Chamilo LMS has unauthenticated access to Twig template source files exposes application logic

Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET requests. These templates expose internal application logic, variable names, AJAX endpoint URLs, and admin panel struct…

πŸ“… Published: April 10, 2026, 6:32 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.1

CVSS3.1

CVE-2026-33704 - Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on the server via the BigUpload endpoint. The key parameter controls the filename and the raw POST body becomes the file content. While .php extensions are…

πŸ“… Published: April 10, 2026, 6:30 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.1

CVSS4.0

CVE-2026-33703 - Chamilo LMS Critical IDOR: Any Authenticated User Can Extract All Users’ Personal Data and API Toke…

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/personal-data/{userId} endpoint allows any authenticated user to access full personal data and API tokens of arbitrary users by modifying the userId para…

πŸ“… Published: April 10, 2026, 6:23 p.m. πŸ”„ Last Modified: April 10, 2026, 7:16 p.m.
Total resulsts: 343924
Page 7 of 34,393
Β« previous page Β» next page
Filters