Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

128 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.24%💥 PoCChamilo LMS16/1/202617/6/2026
An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout because proper cache-control is missing. Using the browser back button restores all personal data, allowing unauthorized users on the same device to view confidential…
AplazadaMedia (5.4)0.34%💥 PoCChamilo LMSAI16/4/202517/6/2026
A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.
AnalizadaMedia (5.4)0.34%—Chamilo LMS15/11/202417/6/2026
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.
AnalizadaAlta (7.5)0.38%—Chamilo LMS4/11/202417/6/2026
Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.php?a=get_count_message" AND "/main/inc/ajax/online.ajax.php?a=get_users_online."
AnalizadaMedia (6.1)0.39%—Chamilo LMS4/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'.
AnalizadaMedia (5.4)0.18%—Chamilo LMS4/11/202417/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.
AnalizadaAlta (8.8)0.60%—Chamilo LMS4/11/202417/6/2026
Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity.
AnalizadaMedia (4.6)0.40%—Chamilo LMS1/11/202417/6/2026
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the home.php component.
AnalizadaAlta (7.1)0.71%—Chamilo LMS1/11/202417/6/2026
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component.
ModificadaAlta (8.8)2.5%💥 PoCChamilo LMS28/11/202317/6/2026
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
ModificadaAlta (8.8)1.8%—Chamilo LMS28/11/202317/6/2026
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
ModificadaAlta (8.8)1.8%—Chamilo LMS28/11/202317/6/2026
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
ModificadaAlta (8.8)1.8%—Chamilo LMS28/11/202317/6/2026
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
ModificadaAlta (8.8)3.5%—Chamilo LMS28/11/202317/6/2026
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
ModificadaAlta (8.8)3.5%—Chamilo LMS28/11/202317/6/2026
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
ModificadaMedia (6.1)76%💥 ExploitChamilo LMS28/11/202317/6/2026
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
ModificadaMedia (4.9)0.73%—Chamilo LMS1/9/202317/6/2026
SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.
ModificadaCrítica (9.8)1.1%—Chamilo LMS13/6/20239/7/2026
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
ModificadaAlta (8.1)0.74%—Chamilo LMS8/6/202317/6/2026
Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.
ModificadaMedia (6.1)0.40%—Chamilo LMS8/6/202317/6/2026
Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.
ModificadaMedia (5.3)0.61%—Chamilo LMS8/6/202317/6/2026
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.
ModificadaMedia (4.3)0.41%—Chamilo LMS8/6/202317/6/2026
Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.
ModificadaMedia (5.4)0.42%—Chamilo LMS9/5/20239/7/2026
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function.
ModificadaMedia (5.4)0.42%—Chamilo LMS9/5/20239/7/2026
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function.
ModificadaMedia (4.8)0.42%—Chamilo LMS9/5/20239/7/2026
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local authenticated attacker to execute arbitrary code via the homepage function.
Orbitaley — Vulnerabilidades