9.3

CVSS4.0

CVE-2026-33698 - Chamilo LMS affected by unauthenticated RCE in main/install folder

Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals wi…

πŸ“… Published: April 10, 2026, 6:14 p.m. πŸ”„ Last Modified: April 15, 2026, 3 p.m.

8.8

CVSS3.1

CVE-2026-33618 - Chamilo LMS Affected by Remote Code Execution via eval() in Platform Settings

Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() to parse platform settings from the database. An attacker with admin access (obtainable via Advisory 1) can inject arbitrary PHP code into the settings…

πŸ“… Published: April 10, 2026, 6:10 p.m. πŸ”„ Last Modified: April 13, 2026, 12:43 p.m.

6.5

CVSS3.1

CVE-2026-33141 - Chamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Data

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endpoint allows any authenticated user (including low-privilege students with ROLE_USER) to read any other user's learning progress, certificates, and gra…

πŸ“… Published: April 10, 2026, 6:01 p.m. πŸ”„ Last Modified: April 14, 2026, 2:06 p.m.

9.1

CVSS3.1

CVE-2026-32892 - OS Command Injection in Chamilo LMS 1.11.36

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapesh…

πŸ“… Published: April 10, 2026, 5:56 p.m. πŸ”„ Last Modified: April 14, 2026, 2:07 p.m.

5.7

CVSS4.0

CVE-2026-1502 - HTTP client proxy tunnel headers not validated for CR/LF

CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.

πŸ“… Published: April 10, 2026, 5:54 p.m. πŸ”„ Last Modified: April 14, 2026, 4:36 p.m.

4.7

CVSS3.1

CVE-2026-32932 - Chamilo LMS has an Open Redirect via Unvalidated 'page' Parameter in Session Course Edit

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the session course edit page allows an attacker to redirect an authenticated administrator to an arbitrary external URL after saving coach assignment changes. The redirect also leaks the …

πŸ“… Published: April 10, 2026, 5:51 p.m. πŸ”„ Last Modified: April 13, 2026, 3:36 p.m.

7.5

CVSS3.1

CVE-2026-32931 - Chamilo LMS has Arbitrary File Upload via MIME-Only Validation in Exercise Sound Upload Leads to RCE

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload function allows an authenticated teacher to upload a PHP webshell by spoofing the Content-Type header to audio/mpeg. The uploaded file retains its ori…

πŸ“… Published: April 10, 2026, 5:50 p.m. πŸ”„ Last Modified: April 15, 2026, 2:56 p.m.

7.1

CVSS3.1

CVE-2026-32930 - Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Evaluation Edit Without Ownership Check

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook evaluation edit page allows any authenticated teacher to view and modify the settings (name, max score, weight) of evaluations belonging to any oth…

πŸ“… Published: April 10, 2026, 5:48 p.m. πŸ”„ Last Modified: April 13, 2026, 12:43 p.m.

7.1

CVSS3.1

CVE-2026-32894 - Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Deletion of Any Student's Grade Result

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook result view page allows any authenticated teacher to delete any student's grade result across the entire platform by manipulating the delete_mark o…

πŸ“… Published: April 10, 2026, 5:44 p.m. πŸ”„ Last Modified: April 13, 2026, 4:16 p.m.

5.4

CVSS3.1

CVE-2026-32893 - Chamilo LMS has Reflected XSS via Unsanitized http_build_query() in Exercise Question List Paginati…

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting (XSS) vulnerability in the exercise question list admin panel allows an attacker to execute arbitrary JavaScript in an authenticated teacher's browser. The pagination code merges all $_GET parameters …

πŸ“… Published: April 10, 2026, 5:42 p.m. πŸ”„ Last Modified: April 15, 2026, 2:51 p.m.
Total resulsts: 344795
Page 95 of 34,480
Β« previous page Β» next page
Filters