Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

chamilo — Vulnerabilities & Security Advisories 83

Browse all 83 CVE security advisories affecting chamilo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Chamilo is an open-source learning management system designed for educational institutions and corporate training environments, facilitating online course delivery and student management. Security audits reveal a significant history of vulnerabilities, with eighty-three Common Vulnerabilities and Exposures (CVEs) currently documented. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and weak access controls in older versions. Notable incidents include arbitrary file upload vulnerabilities that allowed attackers to execute malicious scripts on the server, compromising system integrity. The platform’s reliance on legacy PHP frameworks has contributed to these recurring security issues, necessitating rigorous patching and configuration hardening. While newer iterations have improved security postures, the extensive CVE record highlights the critical need for continuous monitoring and secure coding practices to mitigate risks associated with its widespread deployment in academic settings.

High2026-04-18
Security: Add `CourseRelUserStateProcessor` and improve course catalo… · chamilo/chamilo-lms@2a9f060 · GitHub
Unknown2026-04-18
Security: Social: allow only images and videos in social post attachm… · chamilo/chamilo-lms@7c4965e · GitHub
High2026-04-18
Security: Ensure SVG files are sanitized and properly served download · chamilo/chamilo-lms@da671d6 · GitHub
High2026-04-18
Security: Refactor URL validation logic to ensure stricter checks aga… · chamilo/chamilo-lms@de4058d · GitHub
High2026-04-18
Feature: Add custom state provider for CourseRelUser collection to ha… · chamilo/chamilo-lms@c9c30cd · GitHub
HighCVE-2026-308812026-04-18
Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2) · Advisory · chamilo/chamilo-lms · GitH
MediumGHSA-273p-jw9w-3g222026-04-18
Stored XSS via Malicious File Upload in Social Post Attachments Leading to Arbitrary JavaScript Execution (<=2.0-RC.2) ·
HighCVE-2026-341602026-04-18
Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and reach cloud metadata services (<=2.0-
High2026-04-18
Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action (<=2.0-RC.2) · Advisory · chamilo/cham
HighCVE-2026-351962026-04-18
OS Command Injection on Chamilo LMS · Advisory · chamilo/chamilo-lms · GitHub
High2026-04-18
IDOR in /api/course_rel_users Allows Unauthorized Enrollment of Arbitrary Users into Courses (<=2.0-RC.2) · Advisory · c
Medium2026-04-11
Open Redirect via Unvalidated 'page' Parameter in Session Course Edit (2.0.0 RC) · Advisory · chamilo/chamilo-lms · GitH
High2026-04-11
IDOR in Gradebook Allows Cross-Course Deletion of Any Student's Grade Result (2.0.0 RC) · Advisory · chamilo/chamilo-lms
HighGHSA-hc3c-8p55-xh4r2026-03-03
Security: Apply XSS removal when importing users · chamilo/chamilo-lms@790ef51 · GitHub
HighCVE-2025-501952026-03-03
OS Command Injection · Advisory · chamilo/chamilo-lms · GitHub
High2026-03-03
OS Command Injection · Advisory · chamilo/chamilo-lms · GitHub
HighCVE-2025-501972026-03-03
OS Command Injection (<=1.11.28) · Advisory · chamilo/chamilo-lms · GitHub
HighGHSA-xrr6-wv8p-5v3p2026-03-03
OS Command Injection · Advisory · chamilo/chamilo-lms · GitHub
High2026-03-03
Security: Add 'auth_openid_allowed_providers' configuration setting t… · chamilo/chamilo-lms@43a9bd1 · GitHub
HighCVE-2024-478862026-03-03
Chamilo 1.11.26 - Post-Auth Remote Code Execution · Advisory · chamilo/chamilo-lms · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with chamilo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.