VendorsChamilochamilo_lmsall versions
Vulnerabilities

Chamilo LMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

122CVEs
CVE-2024-47886
Chamilo: Post-Auth Remote Code Execution
Published 2026-03-02 · Analyzed
8.7EPSS 0.009
CVE-2026-34160
Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services
Published 2026-04-14 · Analyzed
8.6EPSS 0.006
CVE-2026-31939
Path Traversal (Arbitrary File Delete) in Chamilo LMS
Published 2026-04-10 · Analyzed
8.3EPSS 0.005
CVE-2025-52482
Chamilo: Stored XSS in glossary function via /main/glossary/index.php trigger in /main/tracking/course_log_resources.php
Published 2026-03-02 · Analyzed
8.3EPSS 0.004
CVE-2023-4220
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
Published 2023-11-28 · Modified
8.11 PoCEPSS 0.761
CVE-2018-20329
Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information.
Published 2018-12-21 · Modified
8.1EPSS 0.012
CVE-2023-34962
Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.
Published 2023-06-08 · Modified
8.1EPSS 0.007
CVE-2025-59541
Chamilo: CSRF Vulnerability in Project Deletion
Published 2026-03-06 · Analyzed
8.1EPSS 0.002
CVE-2026-31941
Server-Side Request Forgery (SSRF) in Chamilo LMS
Published 2026-04-10 · Analyzed
7.7EPSS 0.004
CVE-2012-4030
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.
Published 2020-01-10 · Modified
7.5EPSS 0.013
CVE-2026-33710
Chamilo LMS has Weak REST API Key Generation (Predictable)
Published 2026-04-10 · Analyzed
7.5EPSS 0.005
CVE-2024-30619
Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.php?a=get_count_message" AND "/main/inc/ajax/online.ajax.php?a=get_users_online."
Published 2024-11-04 · Analyzed
7.5EPSS 0.004
CVE-2025-50196
Chamilo: OS Command Injection in /plugin/vchamilo/views/editinstance.php via POST main_database parameter
Published 2026-03-02 · Analyzed
7.2EPSS 0.027
CVE-2025-50195
Chamilo: OS Command Injection in /plugin/vchamilo/views/manage.controller.php
Published 2026-03-02 · Analyzed
7.2EPSS 0.027
CVE-2025-50197
Chamilo: OS Command Injection in /main/admin/sub_language_ajax.inc.php via POST new_language parameter
Published 2026-03-02 · Analyzed
7.2EPSS 0.027
CVE-2025-50193
Chamilo: OS command Injection in /plugin/vchamilo/views/import.php with the POST to_main_database parameter
Published 2026-03-02 · Analyzed
7.2EPSS 0.026
CVE-2025-50194
Chamilo: OS Command Injection in /main/cron/lang/check_parse_lang.php
Published 2026-03-02 · Analyzed
7.2EPSS 0.026
CVE-2022-27421
Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.
Published 2022-04-15 · Modified
7.2EPSS 0.010
CVE-2025-50188
Error-based SQL Injection in Chamilo LMS
Published 2026-03-02 · Analyzed
7.2EPSS 0.007
CVE-2025-50191
Chamilo: Error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php script
Published 2026-03-02 · Analyzed
7.2EPSS 0.005
CVE-2026-33714
Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)
Published 2026-04-14 · Analyzed
7.2EPSS 0.005
CVE-2026-33715
Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action
Published 2026-04-14 · Analyzed
7.2EPSS 0.004
CVE-2024-27524
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component.
Published 2024-11-01 · Analyzed
7.1EPSS 0.007
CVE-2026-32894
Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Deletion of Any Student's Grade Result
Published 2026-04-10 · Analyzed
7.1EPSS 0.004
CVE-2026-33702
Chamilo LMS has an Insecure Direct Object Reference (IDOR)
Published 2026-04-10 · Analyzed
7.1EPSS 0.004
CVE-2026-34602
Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses
Published 2026-04-14 · Analyzed
7.1EPSS 0.004
CVE-2026-32930
Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Evaluation Edit Without Ownership Check
Published 2026-04-10 · Analyzed
7.1EPSS 0.003
CVE-2026-33703
Chamilo LMS Critical IDOR: Any Authenticated User Can Extract All Users’ Personal Data and API Tokens
Published 2026-04-10 · Analyzed
7.1EPSS 0.003
CVE-2025-52469
Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation Bypass
Published 2026-03-02 · Analyzed
7.1EPSS 0.003
CVE-2026-33706
Chamilo LMS has a REST API Self-Privilege Escalation (Student → Teacher)
Published 2026-04-10 · Analyzed
7.1EPSS 0.003
CVE-2025-52564
Chamilo: HTML injection via open parameter
Published 2026-03-02 · Analyzed
6.9EPSS 0.002
CVE-2025-59544
Chamilo: Unauthorized access to update category of any user
Published 2026-03-06 · Analyzed
6.9EPSS 0.002
CVE-2019-1000017
Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all tickets available on the platform, due to lack of access controls. This attack appears to be exploitable via ticket_id=[ticket number]. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.
Published 2019-02-04 · Modified
6.5EPSS 0.010
CVE-2026-34370
Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes
Published 2026-04-14 · Analyzed
6.5EPSS 0.004
CVE-2026-33737
Chamilo LMS has an XML External Entity (XXE) Injection
Published 2026-04-10 · Analyzed
6.5EPSS 0.004
CVE-2026-33736
Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposure
Published 2026-04-10 · Analyzed
6.5EPSS 0.004
CVE-2026-33708
Chamilo LMS has REST API PII Exposure via get_user_info_from_username
Published 2026-04-10 · Analyzed
6.5EPSS 0.004
CVE-2026-33141
Chamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Data
Published 2026-04-10 · Analyzed
6.5EPSS 0.002
CVE-2025-59540
Chamilo: Stored Cross-Site Scripting (XSS) in Chamilo LMS Exercise Feedback
Published 2026-03-06 · Analyzed
6.4EPSS 0.002
CVE-2026-30876
Chamilo LMS: User enumeration vulnerability via response
Published 2026-03-16 · Analyzed
6.3EPSS 0.003
← Prev2 / 4Next →