VendorsChamilochamilo_lmsall versions
Vulnerabilities

Chamilo LMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

122CVEs
CVE-2019-13082
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php file in a folder and then this folder in a ZIP archive, the server will accept this file without any checks. Because one can access this file from the website, it is remote code execution. This is related to a scorm imsmanifest.xml file, the import_package function, and extraction in $courseSysDir.$newDir.
Published 2019-06-30 · Modified
9.8EPSS 0.040
CVE-2018-1999019
Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php that can result in Unauthenticated remote code execution. This attack appear to be exploitable via a simple GET request to the api endpoint. This vulnerability appears to have been fixed in After commit 0de84700648f098c1fbf6b807dee28ec640efe62.
Published 2018-07-23 · Modified
9.8EPSS 0.032
CVE-2021-35414
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.
Published 2021-12-03 · Modified
9.8EPSS 0.018
CVE-2023-34944
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
Published 2023-06-13 · Modified
9.8EPSS 0.011
CVE-2022-27423
Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php.
Published 2022-04-15 · Modified
9.8EPSS 0.010
CVE-2025-50187
Chamilo: Evaluation of untrusted user input leads to Remote Code Execution
Published 2026-03-02 · Analyzed
9.8EPSS 0.009
CVE-2026-33707
Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms
Published 2026-04-10 · Analyzed
9.8EPSS 0.008
CVE-2026-28430
Chamilo LMS Vulnerable to Unauthenticated SQL Injection in chamiko-lms model.ajax.php
Published 2026-03-16 · Analyzed
9.8EPSS 0.006
CVE-2025-50190
Chamilo: Error-based SQL Injection via GET openid.assoc_handle with the /index.php script
Published 2026-03-02 · Analyzed
9.8EPSS 0.006
CVE-2025-50192
Chamilo: Time-based SQL Injection in /main/webservices/registration.soap.php
Published 2026-03-02 · Analyzed
9.8EPSS 0.006
CVE-2026-33698
Chamilo LMS affected by unauthenticated RCE in main/install folder
Published 2026-04-10 · Analyzed
9.8EPSS 0.006
CVE-2025-52998
Chamilo: PHAR deserialization bypass
Published 2026-03-02 · Analyzed
9.8EPSS 0.004
CVE-2026-32892
OS Command Injection in Chamilo LMS 1.11.36
Published 2026-04-10 · Analyzed
9.1EPSS 0.027
CVE-2025-50199
Chamilo: Blind Server-Side Request Forgery (Unauth Blind SSRF)
Published 2026-03-02 · Analyzed
9.1EPSS 0.004
CVE-2025-55208
Chamilo LMS has Stored Cross Site Scripting on Social Networks Uploaded Files
Published 2026-03-05 · Analyzed
9.0EPSS 0.003
CVE-2025-55289
Chamilo: Stored Cross Site Scripting in Skills Argumentation
Published 2026-03-06 · Analyzed
9.0EPSS 0.003
CVE-2025-59542
Chamilo: Account Takeover via Stored XSS in Course Learning Paths
Published 2026-03-06 · Analyzed
9.0EPSS 0.003
CVE-2025-59543
Chamilo: Account Takeover via Stored XSS in Course Description
Published 2026-03-06 · Analyzed
9.0EPSS 0.003
CVE-2023-4221
Chamilo LMS Learning Path PPT2LP Command Injection Vulnerability
Published 2023-11-28 · Modified
8.8EPSS 0.035
CVE-2023-4222
Chamilo LMS Learning Path PPT2LP Command Injection Vulnerability
Published 2023-11-28 · Modified
8.8EPSS 0.035
CVE-2026-35196
Chamilo LMS has OS Command Injection via export_all_certificates action
Published 2026-04-14 · Analyzed
8.8EPSS 0.026
CVE-2021-35413
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
Published 2021-12-03 · Modified
8.8EPSS 0.025
CVE-2023-4226
Chamilo LMS File Upload Functionality Remote Code Execution
Published 2023-11-28 · Modified
8.8EPSS 0.025
CVE-2023-4223
Chamilo LMS File Upload Functionality Remote Code Execution
Published 2023-11-28 · Modified
8.8EPSS 0.018
CVE-2023-4225
Chamilo LMS File Upload Functionality Remote Code Execution
Published 2023-11-28 · Modified
8.8EPSS 0.018
CVE-2023-4224
Chamilo LMS File Upload Functionality Remote Code Execution
Published 2023-11-28 · Modified
8.8EPSS 0.018
CVE-2026-29041
Chamilo: Authenticated Remote Code Execution via Unrestricted File Upload
Published 2026-03-06 · Analyzed
8.8EPSS 0.010
CVE-2026-32931
Chamilo LMS has Arbitrary File Upload via MIME-Only Validation in Exercise Sound Upload Leads to RCE
Published 2026-04-10 · Analyzed
8.8EPSS 0.009
CVE-2026-30875
Chamilo LMS: Authenticated RCE via H5P Import
Published 2026-03-16 · Analyzed
8.8EPSS 0.009
CVE-2022-27426
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
Published 2022-04-15 · Modified
8.8EPSS 0.008
CVE-2020-23127
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
Published 2021-05-05 · Modified
8.8EPSS 0.008
CVE-2026-33704
Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint
Published 2026-04-10 · Analyzed
8.8EPSS 0.008
CVE-2025-50189
Chamilo: Error-based SQL Injection
Published 2026-03-02 · Analyzed
8.8EPSS 0.007
CVE-2024-30616
Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity.
Published 2024-11-04 · Analyzed
8.8EPSS 0.006
CVE-2026-33618
Chamilo LMS Affected by Remote Code Execution via eval() in Platform Settings
Published 2026-04-10 · Analyzed
8.8EPSS 0.006
CVE-2026-30881
Chamilo LMS: SQL Injection in the statistics AJAX endpoint
Published 2026-03-16 · Analyzed
8.8EPSS 0.005
CVE-2026-31940
Session Fixation in Chamilo LMS
Published 2026-04-10 · Analyzed
8.8EPSS 0.005
CVE-2026-40291
Chamilo LMS has Privilege Escalation via API User Role Modification
Published 2026-04-14 · Analyzed
8.8EPSS 0.004
CVE-2025-52468
Chamilo: Stored XSS Vulnerability via CSV User Import
Published 2026-03-02 · Analyzed
8.8EPSS 0.004
CVE-2025-50198
Chamilo: Deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters
Published 2026-03-02 · Analyzed
8.8EPSS 0.003
1 / 4Next →