Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33737

22
FAUCET Score

OVERVIEW CVE-2026-33737 affects Chamilo LMS, a learning management system, in versions prior to 1.11.38 and 2.0.0-RC.3. The vulnerability stems from improper use of the simplexml_load_string() function without XXE (XML External Entity) protection. When the LIBXML_NOENT flag is enabled, attackers can exploit this flaw to read arbitrary files from the affected server. SEVERITY This vulnerability carries a CVSS 3.1 score of 6.5 (MEDIUM severity) with a network-based attack vector requiring low complexity and low privilege user credentials. The attack requires no user interaction and compromises confidentiality by allowing unauthorized file access, though integrity and availability remain unaffected. The FAUCET Risk Score of 35.0 indicates moderate organizational risk. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog, and community attention remains minimal as indicated by the inactive Hot List status. The extremely low EPSS score of 0.0003 suggests this vulnerability ranks well below average in terms of real-world exploitation probability compared to other disclosed CVEs.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.11.38CPE matchmatch criteria
cpe:2.3:a:chamilo:chamilo_lms:*:*:*:*:*:*:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha1:*:*:*:*:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha2:*:*:*:*:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha3:*:*:*:*:*:*
2.0.0CPE matchmatch criteria
cpe:2.3:a:chamilo:chamilo_lms:2.0.0:alpha4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
12.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 12th percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / chamilo/chamilo-lms/commit/22b1cb1c609b643765c88654155aba27070c927e
Patch
github.com / chamilo/chamilo-lms/commit/af6b7002af7c15825e98fc522e2ead0d00cacaa3
Patch
github.com / chamilo/chamilo-lms/security/advisories/GHSA-c4ww-qgf2-v89j
Vendor Advisory