chamilo CVE Vulnerabilities & Metrics

Focus on chamilo vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About chamilo Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with chamilo. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total chamilo CVEs: 69
Earliest CVE date: 05 Dec 2013, 18:55 UTC
Latest CVE date: 28 Nov 2023, 08:15 UTC

Latest CVE reference: CVE-2023-4226

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical chamilo CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.57

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 40
4.0-6.9 25
7.0-8.9 5
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS chamilo CVEs

These are the five CVEs with the highest CVSS scores for chamilo, sorted by severity first and recency.

All CVEs for chamilo

CVE-2023-4226 chamilo vulnerability CVSS: 0 28 Nov 2023, 08:15 UTC

Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

CVE-2023-4225 chamilo vulnerability CVSS: 0 28 Nov 2023, 08:15 UTC

Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

CVE-2023-4224 chamilo vulnerability CVSS: 0 28 Nov 2023, 08:15 UTC

Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

CVE-2023-4223 chamilo vulnerability CVSS: 0 28 Nov 2023, 08:15 UTC

Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

CVE-2023-4222 chamilo vulnerability CVSS: 0 28 Nov 2023, 08:15 UTC

Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.

CVE-2023-4221 chamilo vulnerability CVSS: 0 28 Nov 2023, 08:15 UTC

Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.

CVE-2023-4220 chamilo vulnerability CVSS: 0 28 Nov 2023, 08:15 UTC

Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

CVE-2023-3545 chamilo vulnerability CVSS: 0 28 Nov 2023, 07:15 UTC

Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.

CVE-2023-3533 chamilo vulnerability CVSS: 0 28 Nov 2023, 07:15 UTC

Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write.

CVE-2023-3368 chamilo vulnerability CVSS: 0 28 Nov 2023, 07:15 UTC

Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.

CVE-2023-39582 chamilo vulnerability CVSS: 0 01 Sep 2023, 16:15 UTC

SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions.

CVE-2023-39061 chamilo vulnerability CVSS: 0 21 Aug 2023, 17:15 UTC

Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code.

CVE-2023-34960 chamilo vulnerability CVSS: 0 01 Aug 2023, 02:15 UTC

A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.

CVE-2023-37067 chamilo vulnerability CVSS: 0 07 Jul 2023, 17:15 UTC

Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section.

CVE-2023-37066 chamilo vulnerability CVSS: 0 07 Jul 2023, 17:15 UTC

Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel.

CVE-2023-37065 chamilo vulnerability CVSS: 0 07 Jul 2023, 17:15 UTC

Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.

CVE-2023-37064 chamilo vulnerability CVSS: 0 07 Jul 2023, 17:15 UTC

Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.

CVE-2023-37063 chamilo vulnerability CVSS: 0 07 Jul 2023, 17:15 UTC

Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.

CVE-2023-37062 chamilo vulnerability CVSS: 0 07 Jul 2023, 17:15 UTC

Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.

CVE-2023-37061 chamilo vulnerability CVSS: 0 07 Jul 2023, 17:15 UTC

Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.

CVE-2023-34944 chamilo vulnerability CVSS: 0 13 Jun 2023, 21:15 UTC

An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVE-2023-34962 chamilo vulnerability CVSS: 0 08 Jun 2023, 19:15 UTC

Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes.

CVE-2023-34961 chamilo vulnerability CVSS: 0 08 Jun 2023, 19:15 UTC

Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field.

CVE-2023-34959 chamilo vulnerability CVSS: 0 08 Jun 2023, 19:15 UTC

An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools.

CVE-2023-34958 chamilo vulnerability CVSS: 0 08 Jun 2023, 19:15 UTC

Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.

CVE-2023-31807 chamilo vulnerability CVSS: 0 09 May 2023, 16:15 UTC

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function.

CVE-2023-31806 chamilo vulnerability CVSS: 0 09 May 2023, 16:15 UTC

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function.

CVE-2023-31805 chamilo vulnerability CVSS: 0 09 May 2023, 16:15 UTC

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local authenticated attacker to execute arbitrary code via the homepage function.

CVE-2023-31804 chamilo vulnerability CVSS: 0 09 May 2023, 16:15 UTC

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameters.

CVE-2023-31803 chamilo vulnerability CVSS: 0 09 May 2023, 16:15 UTC

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the resource sequencing parameters.

CVE-2023-31802 chamilo vulnerability CVSS: 0 09 May 2023, 16:15 UTC

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url parameters.

CVE-2023-31801 chamilo vulnerability CVSS: 0 09 May 2023, 16:15 UTC

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter.

CVE-2023-31800 chamilo vulnerability CVSS: 0 09 May 2023, 16:15 UTC

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter.

CVE-2023-31799 chamilo vulnerability CVSS: 0 09 May 2023, 16:15 UTC

Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the system annnouncements parameter.

CVE-2022-42029 chamilo vulnerability CVSS: 0 17 Oct 2022, 18:15 UTC

Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads' to copy/move files from anywhere in the file system into the web directory.

CVE-2022-40407 chamilo vulnerability CVSS: 0 29 Sep 2022, 14:15 UTC

A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file.

CVE-2022-27426 chamilo vulnerability CVSS: 6.5 15 Apr 2022, 20:15 UTC

A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.

CVE-2022-27425 chamilo vulnerability CVSS: 4.3 15 Apr 2022, 20:15 UTC

Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.php.

CVE-2022-27423 chamilo vulnerability CVSS: 7.5 15 Apr 2022, 20:15 UTC

Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php.

CVE-2022-27422 chamilo vulnerability CVSS: 4.3 15 Apr 2022, 20:15 UTC

A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL.

CVE-2022-27421 chamilo vulnerability CVSS: 6.5 15 Apr 2022, 20:15 UTC

Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.

CVE-2021-40662 chamilo vulnerability CVSS: 6.8 21 Mar 2022, 21:15 UTC

A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.

CVE-2021-38745 chamilo vulnerability CVSS: 4.6 21 Mar 2022, 21:15 UTC

Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.

CVE-2021-35415 chamilo vulnerability CVSS: 3.5 03 Dec 2021, 22:15 UTC

A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.

CVE-2021-35414 chamilo vulnerability CVSS: 7.5 03 Dec 2021, 22:15 UTC

Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.

CVE-2021-35413 chamilo vulnerability CVSS: 6.0 03 Dec 2021, 22:15 UTC

A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.

CVE-2021-43687 chamilo vulnerability CVSS: 4.3 01 Dec 2021, 16:15 UTC

chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.

CVE-2020-23126 chamilo vulnerability CVSS: 4.3 03 Nov 2021, 17:15 UTC

Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.

CVE-2021-37391 chamilo vulnerability CVSS: 3.5 10 Aug 2021, 20:15 UTC

A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send invitation feature.

CVE-2021-37390 chamilo vulnerability CVSS: 4.3 10 Aug 2021, 20:15 UTC

A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).

CVE-2021-37389 chamilo vulnerability CVSS: 4.3 10 Aug 2021, 20:15 UTC

Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.

CVE-2021-34187 chamilo vulnerability CVSS: 7.5 28 Jun 2021, 16:15 UTC

main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.

CVE-2021-32925 chamilo vulnerability CVSS: 5.5 13 May 2021, 18:15 UTC

admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.

CVE-2020-23128 chamilo vulnerability CVSS: 4.0 06 May 2021, 13:15 UTC

Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.

CVE-2020-23127 chamilo vulnerability CVSS: 6.8 06 May 2021, 13:15 UTC

Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.

CVE-2021-31933 chamilo vulnerability CVSS: 6.5 30 Apr 2021, 21:15 UTC

A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code into specific directories via main/inc/lib/fileUpload.lib.php directory traversal to achieve PHP code execution.

CVE-2021-26746 chamilo vulnerability CVSS: 4.3 19 Feb 2021, 05:15 UTC

Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.

CVE-2012-4029 chamilo vulnerability CVSS: 4.3 08 Feb 2020, 18:15 UTC

Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action.

CVE-2013-0739 chamilo vulnerability CVSS: 4.3 30 Jan 2020, 14:15 UTC

Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script.

CVE-2013-0738 chamilo vulnerability CVSS: 4.3 30 Jan 2020, 14:15 UTC

Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php.

CVE-2012-4030 chamilo vulnerability CVSS: 6.4 10 Jan 2020, 17:15 UTC

Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.

CVE-2015-9540 chamilo vulnerability CVSS: 5.8 04 Jan 2020, 07:15 UTC

Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.

CVE-2019-13082 chamilo vulnerability CVSS: 7.5 30 Jun 2019, 16:15 UTC

Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php file in a folder and then this folder in a ZIP archive, the server will accept this file without any checks. Because one can access this file from the website, it is remote code execution. This is related to a scorm imsmanifest.xml file, the import_package function, and extraction in $courseSysDir.$newDir.

CVE-2019-1000017 chamilo vulnerability CVSS: 4.0 04 Feb 2019, 21:29 UTC

Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all tickets available on the platform, due to lack of access controls. This attack appears to be exploitable via ticket_id=[ticket number]. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.

CVE-2019-1000015 chamilo vulnerability CVSS: 4.3 04 Feb 2019, 21:29 UTC

Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the Administrator with the XSS to steal cookies. A ticket can be created with a XSS payload in the subject field. This attack appears to be exploitable via <svg/onload=alert(1)> as the payload user on the Subject field. This makes it possible to obtain the cookies of all users that have permission to view the tickets. This vulnerability appears to have been fixed in 1.11.x after commit 33e2692a37b5b6340cf5bec1a84e541460983c03.

CVE-2018-20329 chamilo vulnerability CVSS: 5.5 21 Dec 2018, 06:29 UTC

Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information.

CVE-2018-20328 chamilo vulnerability CVSS: 3.5 21 Dec 2018, 06:29 UTC

Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

CVE-2018-20327 chamilo vulnerability CVSS: 3.5 21 Dec 2018, 06:29 UTC

Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

CVE-2018-1999019 chamilo vulnerability CVSS: 7.5 23 Jul 2018, 15:29 UTC

Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php that can result in Unauthenticated remote code execution. This attack appear to be exploitable via a simple GET request to the api endpoint. This vulnerability appears to have been fixed in After commit 0de84700648f098c1fbf6b807dee28ec640efe62.

CVE-2013-6787 chamilo vulnerability CVSS: 6.0 05 Dec 2013, 18:55 UTC

SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.