← Back

Chamilo

chamilo

148 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Chamilo Lms
chamilo_lms
Chamilo
chamilo

CVEs (148)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Chamilo
1Chamilo
Jun 17, 2026
Mar 21, 2022
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction wit...Show more
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.Show less
1Chamilo
1Chamilo Lms
Jun 17, 2026
Dec 3, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.
1Chamilo
1Chamilo Lms
Jun 17, 2026
Dec 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.
1Chamilo
1Chamilo Lms
Jun 17, 2026
Dec 3, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
1Chamilo
1Chamilo
Jul 9, 2026
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.
1Chamilo
1Chamilo Lms
Jun 17, 2026
Nov 3, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.
1Chamilo
1Chamilo Lms
Jun 17, 2026
Aug 10, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary...Show more
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.Show less
1Chamilo
1Chamilo Lms
Jun 17, 2026
Aug 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
1Chamilo
1Chamilo
Jun 17, 2026
Aug 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
1Chamilo
1Chamilo
Jun 17, 2026
Jun 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.
1Chamilo
1Chamilo
Jun 17, 2026
May 13, 2021
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
1Chamilo
1Chamilo Lms
Jun 17, 2026
May 6, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privile...Show more
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.Show less
1Chamilo
1Chamilo Lms
Jun 17, 2026
May 6, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
1Chamilo
1Chamilo
Jun 17, 2026
Apr 30, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or...Show more
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code into specific directories via main/inc/lib/fileUpload.lib.php directory traversal to achieve PHP code execution.Show less
1Chamilo
1Chamilo
Jun 17, 2026
Feb 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.
1Chamilo
1Chamilo
Nov 21, 2024
Feb 8, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action...Show more
Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action.Show less
1Chamilo
1Chamilo
Nov 21, 2024
Jan 30, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script.
1Chamilo
1Chamilo
Nov 21, 2024
Jan 30, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php.
1Chamilo
1Chamilo Lms
Nov 21, 2024
Jan 10, 2020
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.
1Chamilo
1Chamilo Lms
Nov 21, 2024
Jan 4, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.