← Back

Chamilo

chamilo

Vendor: Chamilo • 26 CVEs

CVEs (26)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chamilo
1Chamilo
Jun 17, 2026
May 13, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
1Chamilo
1Chamilo
Jun 17, 2026
Apr 30, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or...Show more
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code into specific directories via main/inc/lib/fileUpload.lib.php directory traversal to achieve PHP code execution.Show less
1Chamilo
1Chamilo
Jun 17, 2026
Feb 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.
1Chamilo
1Chamilo
Nov 21, 2024
Feb 8, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action...Show more
Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action.Show less
1Chamilo
1Chamilo
Nov 21, 2024
Jan 30, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script.
1Chamilo
1Chamilo
Nov 21, 2024
Jan 30, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php.