VYPR

Chamilo

by Chamilo

Source repositories

CVEs (98)

  • CVE-2021-31933HigApr 30, 2021
    risk 0.04cvss 7.2epss 0.14

    A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to…

  • CVE-2021-34187CriJun 28, 2021
    risk 0.01cvss 9.8epss 0.16

    main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.

  • CVE-2026-39878CriJul 20, 2026
    risk 0.00cvss 9.3epss 0.00

    Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full platform admin account…

  • CVE-2026-34239HigJul 20, 2026
    risk 0.00cvss epss 0.00

    Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`, which means any authenticated user enrolled in a course (student, teacher,…

  • CVE-2025-66447NonApr 10, 2026
    risk 0.00cvss 0.0epss 0.00

    Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through the use of the redirect parameter to /login. This vulnerability is fixed in 2.0-beta.2.

  • CVE-2025-52998CriMar 2, 2026
    risk 0.00cvss 9.8epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary classes, as well as fully control their properties, and thus modify the logic of the…

  • CVE-2025-52564MedMar 2, 2026
    risk 0.00cvss 6.1epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as underlined text, via a crafted URL. This issue has been patched in version 1.11.30.

  • CVE-2025-52476MedMar 2, 2026
    risk 0.00cvss 6.1epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to improper sanitization of the keyword_active parameter in admin/user_list.php. This issue has been patched in version 1.11.30.

  • CVE-2025-52475MedMar 2, 2026
    risk 0.00cvss 6.1epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability in the admin/user_list.php endpoint. The keyword_inactive parameter is not properly sanitized, allowing attackers to inject malicious JavaScript…

  • CVE-2025-52470MedMar 2, 2026
    risk 0.00cvss 4.8epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists in the session_category_add.php script. The vulnerability is caused by improper sanitization of the Category Name field, allowing privileged users to…

  • CVE-2025-52469HigMar 2, 2026
    risk 0.00cvss 7.1epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated user to forcibly add any user as a friend by directly calling the AJAX endpoint. The attacker can…

  • CVE-2025-52468HigMar 2, 2026
    risk 0.00cvss 8.8epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importing user data from CSV files. This flaw occurs due to insufficient sanitization of user data, specifically in the "Last Name", "First Name", and "Username"…

  • CVE-2025-50198MedMar 2, 2026
    risk 0.00cvss 4.9epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters. This issue has been patched in version…

  • CVE-2025-50197HigMar 2, 2026
    risk 0.00cvss 7.2epss 0.03

    Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.inc.php via the POST new_language parameter. This issue has been patched in version 1.11.30.

  • CVE-2025-50196HigMar 2, 2026
    risk 0.00cvss 7.2epss 0.03

    Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinstance.php via the POST main_database parameter. This issue has been patched in version 1.11.30.

  • CVE-2025-50195HigMar 2, 2026
    risk 0.00cvss 7.2epss 0.03

    Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.controller.php. This issue has been patched in version 1.11.30.

  • CVE-2025-50194HigMar 2, 2026
    risk 0.00cvss 7.2epss 0.03

    Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang.php. This issue has been patched in version 1.11.30.

  • CVE-2025-50193HigMar 2, 2026
    risk 0.00cvss 7.2epss 0.03

    Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST to_main_database parameter. This issue has been patched in version 1.11.30.

  • CVE-2025-52482HigMar 2, 2026
    risk 0.00cvss 8.3epss 0.00

    Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.

  • CVE-2025-50192CriMar 2, 2026
    risk 0.00cvss 9.8epss 0.01

    Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30.

Page 4 of 5