CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
Chamilo LMS: Student-to-admin stored XSS in private messages via v-html
Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php
Chamilo Authenticated Remote Code Execution
Chamilo stored XSS via user registration leads to admin account takeover
Chamilo LMS has Privilege Escalation via API User Role Modification
Chamilo LMS has OS Command Injection via export_all_certificates action
Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses
Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes
Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution
Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services
Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action
Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)
Chamilo LMS has an XML External Entity (XXE) Injection
Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposure
Chamilo LMS has Weak REST API Key Generation (Predictable)
Chamilo LMS has REST API PII Exposure via get_user_info_from_username
Weak Password Recovery Mechanism for Forgotten Password in chamilo/chamilo-lms
Chamilo LMS has a REST API Self-Privilege Escalation (Student → Teacher)
Chamilo LMS has unauthenticated access to Twig template source files exposes application logic
Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint
Chamilo LMS Critical IDOR: Any Authenticated User Can Extract All Users’ Personal Data and API Tokens
Chamilo LMS has an Insecure Direct Object Reference (IDOR)
Chamilo LMS affected by unauthenticated RCE in main/install folder
Chamilo LMS Affected by Remote Code Execution via eval() in Platform Settings
Showing 1 to 25 CVEs · page 1 (more available)