Known vulnerabilities in Chamilo LMS - page 4

Vendor: Chamilo
Software: Chamilo LMS
Software CPE: cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*
Total vulnerabilities: 128
Public exploits: 18
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Chamilo LMS Chamilo LMS is affected by 128 known vulnerabilities: 17 high, 39 medium, 72 low Critical High Medium Low

Vulnerabilities (128)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU127573 - Server-Side Request Forgery (SSRF)
CVE-2026-33715
CWE-918 Medium
No
No
2.0.0 RC.3 24.04.2026 SB20260424135
#VU127572 - Improper Authorization
CVE-2026-34370
CWE-285 Low
No
No
2.0.0 RC.3 24.04.2026 SB20260424135
#VU127571 - Server-Side Request Forgery (SSRF)
CVE-2026-34160
CWE-918 High
No
No
2.0.0 RC.3 24.04.2026 SB20260424135
#VU127570 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-34161
CWE-79 Low
No
No
2.0.0 RC.3 24.04.2026 SB20260424135
#VU127569 - Authorization Bypass Through User-Controlled Key
CVE-2026-34602
CWE-639 Low
No
No
2.0.0 RC.3 24.04.2026 SB20260424135
#VU127564 - Authorization Bypass Through User-Controlled Key
CVE-2026-32894
CWE-639 Low
No
No
2.0.0 RC.3 24.04.2026 SB20260424135
#VU127561 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-32932
CWE-601 Medium
No
No
1.11.38, 2.0.0 RC.3 24.04.2026 SB20260424128
#VU127560 - Authorization Bypass Through User-Controlled Key
CVE-2026-33702
CWE-639 Low
No
No
1.11.38 24.04.2026 SB20260424128
#VU127559 - Authorization Bypass Through User-Controlled Key
CVE-2026-33703
CWE-639 Low
No
No
2.0.0 RC.3 24.04.2026 SB20260424135
#VU127558 - Incorrect Authorization
CVE-2026-40291
CWE-863 Medium
No
No
2.0.0 RC.3 24.04.2026 SB20260424135
#VU127557 - Eval Injection
CVE-2026-33618
CWE-95 Medium
No
No
2.0.0 RC.3 24.04.2026 SB20260424135
#VU127556 - Authorization Bypass Through User-Controlled Key
CVE-2026-33736
CWE-639 Low
No
No
2.0.0 RC.3 24.04.2026 SB20260424135
#VU127555 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2026-33737
CWE-611 Low
No
No
1.11.38, 2.0.0 RC.3 24.04.2026 SB20260424128
#VU127554 - Unrestricted Upload of File with Dangerous Type
CVE-2026-33704
CWE-434 Low
No
No
1.11.38 24.04.2026 SB20260424128
#VU127553 - File And Directory Information Exposure
CVE-2026-33705
CWE-538 Medium
No
No
1.11.38 24.04.2026 SB20260424128
#VU127552 - Improper Privilege Management
CVE-2026-33706
CWE-269 Low
No
No
1.11.38 24.04.2026 SB20260424128
#VU127551 - Weak password recovery mechanism
CVE-2026-33707
CWE-640 High
No
No
1.11.38, 2.0.0 RC.3 24.04.2026 SB20260424128
#VU127549 - Use of Insufficiently Random Values
CVE-2026-33710
CWE-330 Medium
No
No
1.11.38 24.04.2026 SB20260424128
#VU127548 - Missing Authorization
CVE-2026-33708
CWE-862 Low
No
No
1.11.38 24.04.2026 SB20260424128
#VU127547 - Improper Access Control
CVE-2026-33698
CWE-284 High
No
No
1.11.38 24.04.2026 SB20260424128


Showing elements 61 - 80 out of 128