Vulnerabilities (CVE)

Filtered by vendor Chamilo Subscribe
Filtered by product Chamilo Lms
Total 122 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-50337 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 5.3 MEDIUM
Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, which results in unauthenticated blind SSRF. This issue has been patched in version 1.11.28.
CVE-2024-47886 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 7.2 HIGH
Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing multiple supported features from the virtualization plugin vchamilo, the vulnerability allows an administrator to execute arbitrary code on the server. This issue has been patched in version 1.11.26.
CVE-2024-30619 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 7.5 HIGH
Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users via "/main/inc/ajax/message.ajax.php?a=get_count_message" AND "/main/inc/ajax/online.ajax.php?a=get_users_online."
CVE-2024-30618 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 6.1 MEDIUM
A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'.
CVE-2024-30617 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 5.4 MEDIUM
A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a fake post onto the user's social wall without their consent or knowledge.
CVE-2024-30616 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 8.8 HIGH
Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity.
CVE-2024-27525 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 4.6 MEDIUM
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the home.php component.
CVE-2024-27524 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 7.1 HIGH
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component.
CVE-2023-4226 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 8.8 HIGH
Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVE-2023-4225 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 8.8 HIGH
Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVE-2023-4224 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 8.8 HIGH
Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVE-2023-4223 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 8.8 HIGH
Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.
CVE-2023-4222 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 7.2 HIGH
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
CVE-2023-4221 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 7.2 HIGH
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
CVE-2023-4220 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 8.1 HIGH
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
CVE-2023-39582 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 4.9 MEDIUM
SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.
CVE-2023-34962 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 8.1 HIGH
Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.
CVE-2023-34961 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 6.1 MEDIUM
Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.
CVE-2023-34959 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 5.3 MEDIUM
An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.
CVE-2023-34958 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 4.3 MEDIUM
Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.