Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2210043
AlmaLinux
5931
Alpaquita
16087
Alpine
4608
Android
3677
Azure Linux
17651
BellSoft Hardened Containers
754
Bitnami
9325
Chainguard
1030749
CleanStart
3846
CRAN
14
crates.io
2738
Debian
68459
Echo
7444
GHC
3
GIT
108258
GitHub Actions
55
Go
9245
Hackage
33
Hex
364
Julia
1713
Linux
29974
Mageia
6231
Maven
7044
MinimOS
144672
npm
228850
NuGet
1869
opam
29
openEuler
8800
openSUSE
14480
OSS-Fuzz
4013
Packagist
7098
Pub
11
PyPI
25181
Red Hat
23387
Rocky Linux
4305
Root
19583
RubyGems
5326
SUSE
23350
SwiftURL
60
TuxCare
9592
Ubuntu
65406
VSCode
21
Wolfi
289807
ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-45140
github.com/chamilo/chamilo-lms
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
17 Sep
Fix available
Severity - 9.8 (Critical)
CVE-2026-45143
github.com/chamilo/chamilo-lms
Chamilo LMS: Student-to-admin stored XSS in private messages via v-html
17 Sep
Fix available
Severity - 9.0 (Critical)
CVE-2026-82535
github.com/chamilo/chamilo-lms
Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php
11 Sep
Fix available
Severity - 5.3 (Medium)
CVE-2026-34239
github.com/chamilo/chamilo-lms
Chamilo Authenticated Remote Code Execution
20 Jul
No fix available
Severity - 7.5 (High)
CVE-2026-39878
github.com/chamilo/chamilo-lms
Chamilo stored XSS via user registration leads to admin account takeover
20 Jul
No fix available
Severity - 9.3 (Critical)
CVE-2026-40291
github.com/chamilo/chamilo-lms
Chamilo LMS has Privilege Escalation via API User Role Modification
14 Apr
No fix available
Severity - 8.8 (High)
CVE-2026-35196
github.com/chamilo/chamilo-lms
Chamilo LMS has OS Command Injection via export_all_certificates action
14 Apr
Fix available
Severity - 8.8 (High)
CVE-2026-34602
github.com/chamilo/chamilo-lms
Chamilo LMS: IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses
14 Apr
Fix available
Severity - 7.1 (High)
CVE-2026-34370
github.com/chamilo/chamilo-lms
Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes
14 Apr
Fix available
Severity - 6.5 (Medium)
CVE-2026-34161
github.com/chamilo/chamilo-lms
Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary JavaScript Execution
14 Apr
Fix available
Severity - 5.1 (Medium)
CVE-2026-34160
github.com/chamilo/chamilo-lms
Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services
14 Apr
Fix available
Severity - 8.6 (High)
CVE-2026-33714
github.com/chamilo/chamilo-lms
Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)
14 Apr
Fix available
Severity - 7.1 (High)
CVE-2026-33737
github.com/chamilo/chamilo-lms
Chamilo LMS has an XML External Entity (XXE) Injection
10 Apr
Fix available
Severity - 5.3 (Medium)
CVE-2026-33736
github.com/chamilo/chamilo-lms
Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposure
10 Apr
Fix available
Severity - 6.5 (Medium)
CVE-2026-33710
github.com/chamilo/chamilo-lms
Chamilo LMS has Weak REST API Key Generation (Predictable)
10 Apr
Fix available
Severity - 7.5 (High)
CVE-2026-33708
github.com/chamilo/chamilo-lms
Chamilo LMS has REST API PII Exposure via get_user_info_from_username
10 Apr
Fix available
Severity - 6.5 (Medium)
Load more...
Vulnerability Database - OSV