Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| chamilo | chamilo-lms | < 1.11.30 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-50187 | 9.8 CRITICAL | Chamilo: Evaluation of untrusted user input leads to Remote Code Execution |
| CVE-2025-52468 | 8.8 HIGH | Chamilo: Stored XSS Vulnerability via CSV User Import |
| CVE-2025-52482 | 8.3 HIGH | Chamilo: Stored XSS in glossary function via /main/glossary/index.php trigger in /main/tra |
| CVE-2025-52469 | 7.1 HIGH | Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation B |
| CVE-2024-50337 | 5.3 MEDIUM | Chamilo: Potential unauthenticated blind SSRF via openid function |
| CVE-2025-50186 | 4.8 MEDIUM | Chamilo: Stored XSS via Malicious CSV Filename in user_import.php |
| CVE-2025-52470 | 4.8 MEDIUM | Chamilo: Stored Cross-Site Scripting (XSS) via Session Category Name |
| CVE-2025-50198 | Chamilo: Deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST c | |
| CVE-2024-47886 | Chamilo: Post-Auth Remote Code Execution | |
| CVE-2025-50199 | Chamilo: Blind Server-Side Request Forgery (Unauth Blind SSRF) | |
| CVE-2025-52476 | Chamilo: Reflected XSS via keyword_active parameter | |
| CVE-2025-52475 | Chamilo: Reflected XSS via keyword_inactive parameter | |
| CVE-2025-52998 | Chamilo: PHAR deserialization bypass | |
| CVE-2025-52564 | Chamilo: HTML injection via open parameter | |
| CVE-2025-52563 | Chamilo: Reflected XSS via page parameter | |
| CVE-2025-50196 | Chamilo: OS Command Injection in /plugin/vchamilo/views/editinstance.php via POST main_dat | |
| CVE-2025-50194 | Chamilo: OS Command Injection in /main/cron/lang/check_parse_lang.php | |
| CVE-2025-50193 | Chamilo: OS command Injection in /plugin/vchamilo/views/import.php with the POST to_main_d | |
| CVE-2025-50195 | Chamilo: OS Command Injection in /plugin/vchamilo/views/manage.controller.php | |
| CVE-2025-50191 | Chamilo: Error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.p |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet