Chamilo Lms

Vendor:

First CVE: Dec 5, 2013 · Active for 12 years

122
Total CVEs
More Total CVEs than 99% of tracked products
13.6
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Chamilo Lms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 5, 2013
12 years ago
Most Recent CVE
Apr 14, 2026
101 days ago

CVE Severity & Scoring

Chamilo Lms122 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local1 (0.8%)
Network120 (98.4%)
Unknown1 (0.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low119 (97.5%)
High2 (1.6%)
Unknown1 (0.8%)
User Interaction
None74 (60.7%)
Unknown1 (0.8%)
Required47 (38.5%)
Privileges Required
Low58 (47.5%)
High20 (16.4%)
None43 (35.2%)
Unknown1 (0.8%)

Top CVEs

Signals from CVEs in this product scope (122 CVEs).

122 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to p
Nov 28, 20236.184NOYES
Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has b
Mar 2, 20269.834NONO
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no
Apr 10, 20269.833NONO
Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQ
Mar 16, 20269.833NONO
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This
Mar 2, 20269.833NONO
Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated
Apr 10, 20269.832NONO
Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patc
Mar 2, 20269.832NONO
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG
Jun 13, 20239.832NONO
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and onc
Jun 30, 20199.832NONO
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() funct
Apr 10, 20268.831NONO

Exploit Exposure

Signals from CVEs in this product scope (122 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.8% of CVEs· 96th percentile
Nuclei
1 CVE
0.8% of CVEs· 96th percentile
ExploitDB
3 CVEs
2.5% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (122 CVEs).

Media Mentions

Signals from CVEs in this product scope (122 CVEs).

Top CNAs Publishing CVEs For Chamilo Lms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0.0267.20.4%00
1.9.416.02.7%01
1.9.216.02.7%01
1.9.016.02.7%01
1.8.8.616.02.7%01
1.8.8.416.02.7%01
1.8.8.216.02.7%01
1.8.7.116.02.7%01
1.8.716.02.7%01
1.8.6.216.02.7%01
1.11.858.12.2%00
1.11.619.83.4%00
1.11.419.83.4%00
1.11.2676.40.4%00
1.11.227.71.8%00
1.11.1895.30.4%00
1.11.1036.60.8%00
1.11.019.83.4%00