VendorsChamilochamilo_lmsall versions
Vulnerabilities

Chamilo LMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

122CVEs
CVE-2021-37390
A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
Published 2021-08-10 · Modified
6.1EPSS 0.008
CVE-2019-1000015
Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the Administrator with the XSS to steal cookies. A ticket can be created with a XSS payload in the subject field. This attack appears to be exploitable via <svg/onload=alert(1)> as the payload user on the Subject field. This makes it possible to obtain the cookies of all users that have permission to view the tickets. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.
Published 2019-02-04 · Modified
6.1EPSS 0.008
CVE-2015-9540
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
Published 2020-01-04 · Modified
6.1EPSS 0.007
CVE-2022-27422
A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL.
Published 2022-04-15 · Modified
6.1EPSS 0.006
CVE-2020-23126
Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.
Published 2021-11-03 · Modified
6.1EPSS 0.006
CVE-2023-31801
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter.
Published 2023-05-09 · Modified
6.1EPSS 0.004
CVE-2023-34961
Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.
Published 2023-06-08 · Modified
6.1EPSS 0.004
CVE-2024-30618
A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'.
Published 2024-11-04 · Analyzed
6.1EPSS 0.004
CVE-2026-32932
Chamilo LMS has an Open Redirect via Unvalidated 'page' Parameter in Session Course Edit
Published 2026-04-10 · Analyzed
6.1EPSS 0.003
CVE-2026-30882
Chamilo LMS: Reflected XSS in the session category listing page
Published 2026-03-16 · Analyzed
6.1EPSS 0.003
CVE-2025-52475
Chamilo: Reflected XSS via keyword_inactive parameter
Published 2026-03-02 · Analyzed
6.1EPSS 0.002
CVE-2025-52476
Chamilo: Reflected XSS via keyword_active parameter
Published 2026-03-02 · Analyzed
6.1EPSS 0.002
CVE-2025-52563
Chamilo: Reflected XSS via page parameter
Published 2026-03-02 · Analyzed
6.1EPSS 0.002
CVE-2013-6787
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.
Published 2013-12-05 · Modified
6.01 PoCEPSS 0.027
CVE-2026-1106
Chamilo LMS Legal Consent SocialController.php deleteLegal improper authorization
Published 2026-01-18 · Analyzed
5.5EPSS 0.004
CVE-2025-69581
An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout because proper cache-control is missing. Using the browser back button restores all personal data, allowing unauthorized users on the same device to view confidential information. This leads to profiling, impersonation, targeted attacks, and significant privacy risks.
Published 2026-01-16 · Analyzed
5.5EPSS 0.002
CVE-2021-37391
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.
Published 2021-08-10 · Modified
5.41 PoCEPSS 0.021
CVE-2018-20328
Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.
Published 2018-12-21 · Modified
5.4EPSS 0.007
CVE-2018-20327
Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.
Published 2018-12-21 · Modified
5.4EPSS 0.006
CVE-2023-31800
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter.
Published 2023-05-09 · Modified
5.4EPSS 0.004
CVE-2023-31802
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url parameters.
Published 2023-05-09 · Modified
5.4EPSS 0.004
CVE-2023-31804
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameters.
Published 2023-05-09 · Modified
5.4EPSS 0.004
CVE-2023-31806
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function.
Published 2023-05-09 · Modified
5.4EPSS 0.004
CVE-2023-31807
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function.
Published 2023-05-09 · Modified
5.4EPSS 0.004
CVE-2024-51142
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.
Published 2024-11-15 · Analyzed
5.4EPSS 0.003
CVE-2026-34161
Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution
Published 2026-04-14 · Analyzed
5.4EPSS 0.003
CVE-2026-32893
Chamilo LMS has Reflected XSS via Unsanitized http_build_query() in Exercise Question List Pagination
Published 2026-04-10 · Analyzed
5.4EPSS 0.002
CVE-2024-30617
A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.
Published 2024-11-04 · Analyzed
5.4EPSS 0.002
CVE-2023-34959
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.
Published 2023-06-08 · Modified
5.3EPSS 0.006
CVE-2026-33705
Chamilo LMS has unauthenticated access to Twig template source files exposes application logic
Published 2026-04-10 · Analyzed
5.3EPSS 0.004
CVE-2024-50337
Chamilo: Potential unauthenticated blind SSRF via openid function
Published 2026-03-02 · Analyzed
5.3EPSS 0.003
CVE-2020-23128
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.
Published 2021-05-05 · Modified
4.9EPSS 0.009
CVE-2023-39582
SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.
Published 2023-09-01 · Modified
4.9EPSS 0.007
CVE-2021-35415
A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.
Published 2021-12-03 · Modified
4.8EPSS 0.009
CVE-2023-31799
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the system annnouncements parameter.
Published 2023-05-09 · Modified
4.8EPSS 0.004
CVE-2023-31803
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the resource sequencing parameters.
Published 2023-05-09 · Modified
4.8EPSS 0.004
CVE-2023-31805
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local authenticated attacker to execute arbitrary code via the homepage function.
Published 2023-05-09 · Modified
4.8EPSS 0.004
CVE-2025-50186
Chamilo: Stored XSS via Malicious CSV Filename in user_import.php
Published 2026-03-02 · Analyzed
4.8EPSS 0.003
CVE-2025-52470
Chamilo: Stored Cross-Site Scripting (XSS) via Session Category Name
Published 2026-03-02 · Analyzed
4.8EPSS 0.002
CVE-2025-66447
Chamilo LMS has validation-less redirect on login page
Published 2026-04-10 · Analyzed
4.7EPSS 0.002
← Prev3 / 4Next →