CVE Tools

Chamilo-lms

74 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Chamilo-lms, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Chamilo-lms CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Chamilo-lms CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-0338
2026-0431
2026-050
2026-060
2026-072
2026-080
2026-093

Severity

How the 74 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1521%
  • High3449%
  • Medium2130%

Latest CVEs

The 15 most recently published vulnerabilities affecting Chamilo-lms.

  1. CVE-2026-45140Chamilo LMS CStudio upload flow allows unauthenticated remote code execution9.8
  2. CVE-2026-45143Chamilo LMS: Student-to-admin stored XSS in private messages via v-html9.0
  3. CVE-2026-82535Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php6.1
  4. CVE-2026-34239Chamilo Authenticated Remote Code Execution—
  5. CVE-2026-39878Chamilo stored XSS via user registration leads to admin account takeover9.3
  6. CVE-2026-40291Chamilo LMS has Privilege Escalation via API User Role Modification8.8
  7. CVE-2026-35196Chamilo LMS has OS Command Injection via export_all_certificates action8.8
  8. CVE-2026-34602Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses7.1
  9. CVE-2026-34370Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes6.5
  10. CVE-2026-34161Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution5.4
  11. CVE-2026-34160Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services8.6
  12. CVE-2026-33715Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action7.2
  13. CVE-2026-33714Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)7.2
  14. CVE-2026-33737Chamilo LMS has an XML External Entity (XXE) Injection5.3
  15. CVE-2026-33736Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposure6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store