VendorsChamilochamilo_lms2.0.0
Vulnerabilities

Chamilo LMS 2.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2026-33707
Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms
Published 2026-04-10 · Analyzed
9.8EPSS 0.008
CVE-2026-32892
OS Command Injection in Chamilo LMS 1.11.36
Published 2026-04-10 · Analyzed
9.1EPSS 0.027
CVE-2026-35196
Chamilo LMS has OS Command Injection via export_all_certificates action
Published 2026-04-14 · Analyzed
8.8EPSS 0.026
CVE-2026-32931
Chamilo LMS has Arbitrary File Upload via MIME-Only Validation in Exercise Sound Upload Leads to RCE
Published 2026-04-10 · Analyzed
8.8EPSS 0.009
CVE-2026-33618
Chamilo LMS Affected by Remote Code Execution via eval() in Platform Settings
Published 2026-04-10 · Analyzed
8.8EPSS 0.006
CVE-2026-31940
Session Fixation in Chamilo LMS
Published 2026-04-10 · Analyzed
8.8EPSS 0.005
CVE-2026-40291
Chamilo LMS has Privilege Escalation via API User Role Modification
Published 2026-04-14 · Analyzed
8.8EPSS 0.004
CVE-2026-34160
Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services
Published 2026-04-14 · Analyzed
8.6EPSS 0.006
CVE-2026-31941
Server-Side Request Forgery (SSRF) in Chamilo LMS
Published 2026-04-10 · Analyzed
7.7EPSS 0.004
CVE-2026-33710
Chamilo LMS has Weak REST API Key Generation (Predictable)
Published 2026-04-10 · Analyzed
7.5EPSS 0.005
CVE-2026-33714
Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)
Published 2026-04-14 · Analyzed
7.2EPSS 0.005
CVE-2026-33715
Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action
Published 2026-04-14 · Analyzed
7.2EPSS 0.004
CVE-2026-32894
Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Deletion of Any Student's Grade Result
Published 2026-04-10 · Analyzed
7.1EPSS 0.004
CVE-2026-33702
Chamilo LMS has an Insecure Direct Object Reference (IDOR)
Published 2026-04-10 · Analyzed
7.1EPSS 0.004
CVE-2026-34602
Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses
Published 2026-04-14 · Analyzed
7.1EPSS 0.004
CVE-2026-32930
Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Evaluation Edit Without Ownership Check
Published 2026-04-10 · Analyzed
7.1EPSS 0.003
CVE-2026-33703
Chamilo LMS Critical IDOR: Any Authenticated User Can Extract All Users’ Personal Data and API Tokens
Published 2026-04-10 · Analyzed
7.1EPSS 0.003
CVE-2026-34370
Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes
Published 2026-04-14 · Analyzed
6.5EPSS 0.004
CVE-2026-33737
Chamilo LMS has an XML External Entity (XXE) Injection
Published 2026-04-10 · Analyzed
6.5EPSS 0.004
CVE-2026-33736
Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposure
Published 2026-04-10 · Analyzed
6.5EPSS 0.004
CVE-2026-33141
Chamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Data
Published 2026-04-10 · Analyzed
6.5EPSS 0.002
CVE-2026-32932
Chamilo LMS has an Open Redirect via Unvalidated 'page' Parameter in Session Course Edit
Published 2026-04-10 · Analyzed
6.1EPSS 0.003
CVE-2026-1106
Chamilo LMS Legal Consent SocialController.php deleteLegal improper authorization
Published 2026-01-18 · Analyzed
5.5EPSS 0.004
CVE-2026-34161
Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution
Published 2026-04-14 · Analyzed
5.4EPSS 0.003
CVE-2026-32893
Chamilo LMS has Reflected XSS via Unsanitized http_build_query() in Exercise Question List Pagination
Published 2026-04-10 · Analyzed
5.4EPSS 0.002
CVE-2025-66447
Chamilo LMS has validation-less redirect on login page
Published 2026-04-10 · Analyzed
4.7EPSS 0.002