VYPR

Lms

by Chamilo

Source repositories

CVEs (151)

  • CVE-2022-27421HigApr 15, 2022
    risk 0.47cvss 7.2epss 0.01

    Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.

  • CVE-2021-38745MedMar 21, 2022
    risk 0.44cvss 6.8epss 0.01

    Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.

  • CVE-2026-31941HigApr 10, 2026
    risk 0.43cvss 7.7epss 0.00

    Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a Server-Side Request Forgery (SSRF) vulnerability in the Social Wall feature. The endpoint read_url_with_open_graph accepts a URL from the user via the social_wall_new_msg_main…

  • CVE-2026-33710HigApr 10, 2026
    risk 0.42cvss 7.5epss 0.00

    Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time() + (user_id * 5) - rand(10000, 10000)). The rand(10000, 10000) call always returns exactly 10000 (min == max), making the formula effectively md5(timestamp +…

  • CVE-2026-32931HigApr 10, 2026
    risk 0.42cvss 7.5epss 0.01

    Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload function allows an authenticated teacher to upload a PHP webshell by spoofing the Content-Type header to audio/mpeg. The uploaded…

  • CVE-2026-31940HigApr 10, 2026
    risk 0.42cvss 7.5epss 0.00

    Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to set the PHP session ID before loading global bootstrap. This leads to session fixation. This vulnerability is fixed in…

  • CVE-2021-32925MedMay 13, 2021
    risk 0.42cvss 6.5epss 0.02

    admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.

  • CVE-2019-1000017MedFeb 4, 2019
    risk 0.42cvss 6.5epss 0.01

    Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all tickets available on the platform, due to lack of access controls. This attack appears to be exploitable…

  • CVE-2025-52563MedMar 2, 2026
    risk 0.40cvss 6.1epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to insufficient sanitization of the page parameter in the session/add_users_to_session.php endpoint. This issue has been patched in version…

  • CVE-2023-31801MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter.

  • CVE-2022-27425MedApr 15, 2022
    risk 0.40cvss 6.1epss 0.01

    Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.php.

  • CVE-2022-27422MedApr 15, 2022
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL.

  • CVE-2021-43687MedDec 1, 2021
    risk 0.40cvss 6.1epss 0.01

    chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.

  • CVE-2020-23126MedNov 3, 2021
    risk 0.40cvss 6.1epss 0.01

    Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.

  • CVE-2021-37390MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.01

    A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).

  • CVE-2021-37389MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.01

    Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.

  • CVE-2021-26746MedFeb 19, 2021
    risk 0.40cvss 6.1epss 0.01

    Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.

  • CVE-2012-4029MedFeb 8, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action.

  • CVE-2013-0739MedJan 30, 2020
    risk 0.40cvss 6.1epss 0.01

    Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script.

  • CVE-2013-0738MedJan 30, 2020
    risk 0.40cvss 6.1epss 0.01

    Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php.

Page 3 of 8