Chamilo
Chamilo LMS: vulnerabilidades y CVE
Chamilo LMS tiene 128 vulnerabilidades publicadas, 76 de ellas en los últimos 12 meses. 16 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE128
Últimos 12 meses76
Críticas16
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-45143 | Crítica (9) | 0.49% | — | 17 sept 2026 | Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in… |
| CVE-2026-45140 | Crítica (9.8) | 1.3% | — | 17 sept 2026 | Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the… |
| CVE-2026-82535 | Media (5.3) | 0.47% | — | 11 sept 2026 | Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic… |
| CVE-2026-39878 | Crítica (9.3) | 0.43% | — | 20 jul 2026 | Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's… |
| CVE-2026-40291 | Alta (8.8) | 0.44% | — | 14 abr 2026 | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in the PUT /api/users/{id} endpoint allows any authenticated user with… |
| CVE-2026-35196 | Alta (8.8) | 2.6% | — | 14 abr 2026 | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/inc/ajax/gradebook.ajax.php endpoint within the export_all_certificates… |
| CVE-2026-34602 | Alta (7.1) | 0.36% | — | 14 abr 2026 | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users endpoint is vulnerable to Insecure Direct Object Reference (IDOR), allowing an authenticated attacker… |
| CVE-2026-34370 | Media (6.5) | 0.39% | — | 14 abr 2026 | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated student to… |
| CVE-2026-34161 | Media (5.1) | 0.30% | — | 14 abr 2026 | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the social post attachment upload functionality, where an… |
| CVE-2026-34160 | Alta (8.6) | 0.57% | — | 14 abr 2026 | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin endpoint at public/plugin/Pens/pens.php is accessible without… |
| CVE-2026-33715 | Alta (7.2) | 0.35% | — | 14 abr 2026 | Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without authentication on fully installed instances because, unlike other AJAX… |
| CVE-2026-33714 | Alta (7.1) | 0.46% | — | 14 abr 2026 | Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint, which is an incomplete fix for CVE-2026-30881. While CVE-2026-30881… |
| CVE-2026-33737 | Media (6.5) | 0.38% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT flag, arbitrary server files can be read. This… |
| CVE-2026-33736 | Media (6.5) | 0.35% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can enumerate all platform users and access personal information (email, phone, roles) via GET… |
| CVE-2026-33710 | Alta (7.5) | 0.49% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time() + (user_id * 5) - rand(10000, 10000)). The rand(10000, 10000) call always returns exactly 10000… |
| CVE-2026-33708 | Media (6.5) | 0.35% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email, first name, last name, user ID, active status) of any user to any… |
| CVE-2026-33707 | Crítica (9.8) | 0.75% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An… |
| CVE-2026-33706 | Alta (7.1) | 0.29% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify their own status field via the update_user_from_username endpoint. A student (status=5) can change… |
| CVE-2026-33705 | Media (5.3) | 0.41% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET requests. These templates expose… |
| CVE-2026-33704 | Alta (8.8) | 0.76% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on the server via the BigUpload endpoint. The key parameter controls the… |
| CVE-2026-33703 | Alta (7.1) | 0.30% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the /social-network/personal-data/{userId} endpoint allows any authenticated user to access… |
| CVE-2026-33702 | Alta (7.1) | 0.43% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Object Reference (IDOR) vulnerability in the Learning Path progress saving endpoint. The file… |
| CVE-2026-33698 | Crítica (9.3) | 0.58% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or… |
| CVE-2026-33618 | Alta (8.8) | 0.56% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() to parse platform settings from the database. An attacker with admin… |
| CVE-2026-33141 | Media (6.5) | 0.23% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endpoint allows any authenticated user (including low-privilege students… |
| CVE-2026-32932 | Media (6.1) | 0.31% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the session course edit page allows an attacker to redirect an authenticated administrator to an arbitrary… |
| CVE-2026-32931 | Alta (8.8) | 0.91% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload function allows an authenticated teacher to upload a PHP webshell by… |
| CVE-2026-32930 | Alta (7.1) | 0.34% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook evaluation edit page allows any authenticated teacher to view and… |
| CVE-2026-32894 | Alta (7.1) | 0.44% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook result view page allows any authenticated teacher to delete any… |
| CVE-2026-32893 | Media (5.4) | 0.24% | — | 10 abr 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting (XSS) vulnerability in the exercise question list admin panel allows an attacker to execute arbitrary JavaScript in an… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.