VendorsChamilochamilo_lmsany version
Vulnerabilities

Chamilo LMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

91CVEs
CVE-2021-37391
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.
Published 2021-08-10 · Modified
5.41 PoCEPSS 0.021
CVE-2026-34161
Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution
Published 2026-04-14 · Analyzed
5.4EPSS 0.003
CVE-2023-34959
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.
Published 2023-06-08 · Modified
5.3EPSS 0.006
CVE-2026-33705
Chamilo LMS has unauthenticated access to Twig template source files exposes application logic
Published 2026-04-10 · Analyzed
5.3EPSS 0.004
CVE-2024-50337
Chamilo: Potential unauthenticated blind SSRF via openid function
Published 2026-03-02 · Analyzed
5.3EPSS 0.003
CVE-2023-39582
SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.
Published 2023-09-01 · Modified
4.9EPSS 0.007
CVE-2021-35415
A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.
Published 2021-12-03 · Modified
4.8EPSS 0.009
CVE-2025-50186
Chamilo: Stored XSS via Malicious CSV Filename in user_import.php
Published 2026-03-02 · Analyzed
4.8EPSS 0.003
CVE-2025-52470
Chamilo: Stored Cross-Site Scripting (XSS) via Session Category Name
Published 2026-03-02 · Analyzed
4.8EPSS 0.002
CVE-2025-66447
Chamilo LMS has validation-less redirect on login page
Published 2026-04-10 · Analyzed
4.7EPSS 0.002
CVE-2023-34958
Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.
Published 2023-06-08 · Modified
4.3EPSS 0.004
← Prev3 / 3