Chamilo Lms
Vendor:
First CVE: Dec 5, 2013 · Active for 12 years
122
Total CVEs
More Total CVEs than 99% of tracked products
13.6
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Chamilo Lms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 5, 2013
12 years ago
Most Recent CVE
Apr 14, 2026
101 days ago
CVE Severity & Scoring
Chamilo Lms122 CVEs
47%
39%
14%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (0.8%)
Network120 (98.4%)
Unknown1 (0.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low119 (97.5%)
High2 (1.6%)
Unknown1 (0.8%)
User Interaction
None74 (60.7%)
Unknown1 (0.8%)
Required47 (38.5%)
Privileges Required
Low58 (47.5%)
High20 (16.4%)
None43 (35.2%)
Unknown1 (0.8%)
Top CVEs
Signals from CVEs in this product scope (122 CVEs).
122 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4220MEDIUM Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to p | Nov 28, 2023 | 6.1 | 84 | NO | YES |
CVE-2025-50187CRITICAL Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has b | Mar 2, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-33707CRITICAL Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no | Apr 10, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-28430CRITICAL Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQ | Mar 16, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-50190CRITICAL Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This | Mar 2, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-33698CRITICAL Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated | Apr 10, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-50192CRITICAL Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patc | Mar 2, 2026 | 9.8 | 32 | NO | NO |
CVE-2023-34944CRITICAL An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG | Jun 13, 2023 | 9.8 | 32 | NO | NO |
CVE-2019-13082CRITICAL Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and onc | Jun 30, 2019 | 9.8 | 32 | NO | NO |
CVE-2026-32892HIGH Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() funct | Apr 10, 2026 | 8.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (122 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.8% of CVEs· 96th percentile
Nuclei
1 CVE
0.8% of CVEs· 96th percentile
ExploitDB
3 CVEs
2.5% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (122 CVEs).
Media Mentions
Signals from CVEs in this product scope (122 CVEs).
Top CNAs Publishing CVEs For Chamilo Lms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.0 | 26 | 7.2 | 0.4% | 0 | 0 |
| 1.9.4 | 1 | 6.0 | 2.7% | 0 | 1 |
| 1.9.2 | 1 | 6.0 | 2.7% | 0 | 1 |
| 1.9.0 | 1 | 6.0 | 2.7% | 0 | 1 |
| 1.8.8.6 | 1 | 6.0 | 2.7% | 0 | 1 |
| 1.8.8.4 | 1 | 6.0 | 2.7% | 0 | 1 |
| 1.8.8.2 | 1 | 6.0 | 2.7% | 0 | 1 |
| 1.8.7.1 | 1 | 6.0 | 2.7% | 0 | 1 |
| 1.8.7 | 1 | 6.0 | 2.7% | 0 | 1 |
| 1.8.6.2 | 1 | 6.0 | 2.7% | 0 | 1 |
| 1.11.8 | 5 | 8.1 | 2.2% | 0 | 0 |
| 1.11.6 | 1 | 9.8 | 3.4% | 0 | 0 |
| 1.11.4 | 1 | 9.8 | 3.4% | 0 | 0 |
| 1.11.26 | 7 | 6.4 | 0.4% | 0 | 0 |
| 1.11.2 | 2 | 7.7 | 1.8% | 0 | 0 |
| 1.11.18 | 9 | 5.3 | 0.4% | 0 | 0 |
| 1.11.10 | 3 | 6.6 | 0.8% | 0 | 0 |
| 1.11.0 | 1 | 9.8 | 3.4% | 0 | 0 |