Skip to content
Threat Feed

Vendor

Chamilo

4 briefs RSS
critical advisory

Chamilo LMS CStudio Unauthenticated Remote Code Execution

An unauthenticated remote code execution vulnerability in the Chamilo LMS CStudio upload flow allows attackers to gain server-level access by exploiting improper file handling (CVE-2026-45140).

PoC Chamilo LMS remote-code-execution web-application critical-vulnerability
1r 2t 1c updated
critical advisory

Chamilo LMS Unrestricted File Upload Leads to Remote Code Execution

An unrestricted file upload vulnerability in Chamilo LMS (CVE-2026-32931) allows an authenticated teacher to upload a PHP webshell, leading to remote code execution.

Chamilo LMS chamilo rce file-upload
2r 1t 1c
critical advisory

Chamilo LMS OS Command Injection Vulnerability (CVE-2026-35196)

Chamilo LMS versions prior to 2.0.0-RC.3 are vulnerable to OS Command Injection via the _cid session variable in the export_all_certificates action, potentially leading to arbitrary command execution.

PoC cve-2026-35196 os command injection chamilo lms web application
2r 1t 1c updated
critical advisory

Chamilo LMS Remote Code Execution via Arbitrary File Upload (CVE-2026-33704)

Chamilo LMS versions prior to 1.11.38 are vulnerable to remote code execution via arbitrary file upload by authenticated users due to insufficient file extension filtering in the BigUpload endpoint, allowing execution of PHP code on servers configured to process .pht files.

Chamilo LMS chamilo lms rce cve-2026-33704
2r 1t 1c