Vendor
Chamilo vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 34 vulnerabilities in Chamilo: 0 in the last 7 days and 3 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-45140, was published on 17 September 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 3
- Critical, all time
- 5
- Exploited in the wild
- 0
About Chamilo
Chamilo is a non-profit association focused on the development of open-source e-learning software.
Chamilo technologies
Latest Chamilo vulnerabilities
- CVE-2026-45140: Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote…criticalCVSS 9.8EPSS 1.3%
- CVE-2026-39878: Chamilo LMS stored XSS in user registration formcriticalCVSS 9.3
- CVE-2026-34239: Chamilo LMS remote code execution in lang.ajax.phpinfoCVSS 7.5
- CVE-2026-40291: Chamilo LMS privilege escalation in API user role modificationhighCVSS 8.8EPSS 0.3%
- CVE-2026-35196: Chamilo LMS OS command injection in gradebook certificate exporthighCVSS 8.8EPSS 1.8%
- CVE-2026-34602: Chamilo LMS IDOR in course enrollment APIhighCVSS 7.1EPSS 0.2%
- CVE-2026-34370: Chamilo LMS IDOR in notebook modulemediumCVSS 6.5EPSS 0.2%
- CVE-2026-34161: Chamilo LMS Stored XSS in social post attachmentsmediumCVSS 5.4EPSS 0.2%
- CVE-2026-34160: Chamilo LMS unauthenticated SSRF in PENS pluginhighCVSS 8.6EPSS 0.3%
- CVE-2026-33715: Chamilo LMS SSRF and open email relay in install.ajax.phphighCVSS 7.2EPSS 0.2%
- CVE-2026-33714: Chamilo LMS SQL injection in statistics AJAX endpointhighCVSS 7.2EPSS 0.3%
- CVE-2026-33737: Chamilo LMS XML External Entity injection in multiple componentsmediumCVSS 5.3
- CVE-2026-33736: Chamilo LMS authorization bypass in User APImediumCVSS 6.5
- CVE-2026-33710: Chamilo LMS predictable REST API key generationhighCVSS 7.5
- CVE-2026-33708: Chamilo LMS information disclosure in REST APImediumCVSS 6.5
- CVE-2026-33707: Chamilo LMS weak password recovery mechanism in login.lib.phpcriticalCVSS 9.4
- CVE-2026-33706: Chamilo LMS privilege escalation in REST APIhighCVSS 7.1
- CVE-2026-33705: Chamilo LMS information disclosure in Twig templatesmediumCVSS 5.3
- CVE-2026-33704: Chamilo LMS remote code execution via BigUpload endpointhighCVSS 7.1
- CVE-2026-33703: Chamilo LMS IDOR in social-network personal-data endpointmediumCVSS 6.5
- CVE-2026-33702: Chamilo LMS IDOR in Learning Path progress saving endpointhighCVSS 7.1
- CVE-2026-33698: Chamilo LMS unauthenticated RCE in main/install directorycriticalCVSS 9.8
- CVE-2026-33618: Chamilo LMS eval injection in PlatformConfigurationControllerhighCVSS 8.8
- CVE-2026-33141: Chamilo LMS IDOR in REST API stats endpointmediumCVSS 6.5
- CVE-2026-32932: Chamilo LMS open redirect in session course edit pagemediumCVSS 4.7
Most severe Chamilo vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-45140: Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote…criticalCVSS 9.8EPSS 1.3%
- CVE-2026-33698: Chamilo LMS unauthenticated RCE in main/install directorycriticalCVSS 9.8
- CVE-2026-33707: Chamilo LMS weak password recovery mechanism in login.lib.phpcriticalCVSS 9.4
- CVE-2026-39878: Chamilo LMS stored XSS in user registration formcriticalCVSS 9.3
- CVE-2026-32892: Chamilo LMS OS command injection in file move functioncriticalCVSS 9.1
- CVE-2026-35196: Chamilo LMS OS command injection in gradebook certificate exporthighCVSS 8.8EPSS 1.8%
- CVE-2026-40291: Chamilo LMS privilege escalation in API user role modificationhighCVSS 8.8EPSS 0.3%
- CVE-2026-33618: Chamilo LMS eval injection in PlatformConfigurationControllerhighCVSS 8.8
- CVE-2026-34160: Chamilo LMS unauthenticated SSRF in PENS pluginhighCVSS 8.6EPSS 0.3%
- CVE-2026-31939: Chamilo LMS path traversal in savescores.phphighCVSS 8.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 2 | 1 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 1 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/chamilo.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Chamilo vulnerabilities", https://junglewise.ai/threats/vendors/chamilo, 26 September 2026.