7.1

CVSS3.1

CVE-2026-33704 - Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on the server via the BigUpload endpoint. The key parameter controls the filename and the raw POST body becomes the file content. While .php extensions areโ€ฆ

๐Ÿ“… Published: April 10, 2026, 6:30 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.1

CVSS4.0

CVE-2026-33703 - Chamilo LMS Critical IDOR: Any Authenticated User Can Extract All Usersโ€™ Personal Data and API Tokeโ€ฆ

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/personal-data/{userId} endpoint allows any authenticated user to access full personal data and API tokens of arbitrary users by modifying the userId paraโ€ฆ

๐Ÿ“… Published: April 10, 2026, 6:23 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 7:16 p.m.

6

CVSS4.0

CVE-2026-3446 - Base64 decoding stops at first padded quad by default

When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "valiโ€ฆ

๐Ÿ“… Published: April 10, 2026, 6:17 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 7:16 p.m.

7.1

CVSS3.1

CVE-2026-33702 - Chamilo LMS has an Insecure Direct Object Reference (IDOR)

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Object Reference (IDOR) vulnerability in the Learning Path progress saving endpoint. The file lp_ajax_save_item.php accepts a uid (user ID) parameter directly from $_REQUEST and useโ€ฆ

๐Ÿ“… Published: April 10, 2026, 6:15 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 7:16 p.m.

9.3

CVSS4.0

CVE-2026-33698 - Chamilo LMS affected by unauthenticated RCE in main/install folder

Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals wiโ€ฆ

๐Ÿ“… Published: April 10, 2026, 6:14 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 7:16 p.m.

8.8

CVSS3.1

CVE-2026-33618 - Chamilo LMS Affected by Remote Code Execution via eval() in Platform Settings

Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() to parse platform settings from the database. An attacker with admin access (obtainable via Advisory 1) can inject arbitrary PHP code into the settingsโ€ฆ

๐Ÿ“… Published: April 10, 2026, 6:10 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 7:16 p.m.

6.5

CVSS3.1

CVE-2026-33141 - Chamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Data

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endpoint allows any authenticated user (including low-privilege students with ROLE_USER) to read any other user's learning progress, certificates, and graโ€ฆ

๐Ÿ“… Published: April 10, 2026, 6:01 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 6:16 p.m.

9.1

CVSS3.1

CVE-2026-32892 - OS Command Injection in Chamilo LMS 1.11.36

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapeshโ€ฆ

๐Ÿ“… Published: April 10, 2026, 5:56 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 6:16 p.m.

5.7

CVSS4.0

CVE-2026-1502 - HTTP client proxy tunnel headers not validated for CR/LF

CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.

๐Ÿ“… Published: April 10, 2026, 5:54 p.m. ๐Ÿ”„ Last Modified: April 11, 2026, 4:39 a.m.

4.7

CVSS3.1

CVE-2026-32932 - Chamilo LMS has an Open Redirect via Unvalidated 'page' Parameter in Session Course Edit

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the session course edit page allows an attacker to redirect an authenticated administrator to an arbitrary external URL after saving coach assignment changes. The redirect also leaks the โ€ฆ

๐Ÿ“… Published: April 10, 2026, 5:51 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 6:16 p.m.
Total resulsts: 343926
Page 8 of 34,393
ยซ previous page ยป next page
Filters