← Back

Chamilo

chamilo

Vendor: Chamilo • 26 CVEs

CVEs (26)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chamilo
1Chamilo
Jun 17, 2026
Nov 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code...Show more
Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.Show less
1Chamilo
1Chamilo
Jun 17, 2026
Nov 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote c...Show more
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write.Show less
1Chamilo
1Chamilo
Jun 17, 2026
Nov 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a...Show more
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.Show less
1Chamilo
1Chamilo
Jul 9, 2026
Aug 21, 2023
N/A· v4
3.5 LOW· v3
N/A· v2
Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code.
1Chamilo
1Chamilo
Jul 9, 2026
Aug 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
1Chamilo
1Chamilo
Jun 17, 2026
Jul 7, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.
1Chamilo
1Chamilo
Jun 17, 2026
Jul 7, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.
1Chamilo
1Chamilo
Jun 17, 2026
Jul 7, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.
1Chamilo
1Chamilo
Jun 17, 2026
Jul 7, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.
1Chamilo
1Chamilo
Jun 17, 2026
Jul 7, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.
1Chamilo
1Chamilo
Jun 17, 2026
Jul 7, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.
1Chamilo
1Chamilo
Jun 17, 2026
Jul 7, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.
1Chamilo
1Chamilo
Jun 17, 2026
Oct 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads' to copy/move files from anywhere in the file system into the web direc...Show more
Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads' to copy/move files from anywhere in the file system into the web directory.Show less
1Chamilo
1Chamilo
Jun 17, 2026
Sep 29, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.
1Chamilo
1Chamilo
Jun 17, 2026
Apr 15, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.php.
1Chamilo
1Chamilo
Jun 17, 2026
Mar 21, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.
1Chamilo
1Chamilo
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction wit...Show more
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.Show less
1Chamilo
1Chamilo
Jul 9, 2026
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.
1Chamilo
1Chamilo
Jun 17, 2026
Aug 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
1Chamilo
1Chamilo
Jun 17, 2026
Jun 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.