Security: chamilo/chamilo-lms
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
SQL Injection in ExtraField::get_where_clause() via unescaped array filter values (<1.11.42, <2.0.3)GHSA-7whw-8467-78jp published
Aug 4, 2026 by ywarnierHigh -
Incomplete fix for CVE-2026-31941 SSRF: OpenGraph fetch path reachable via redirect and DNS rebinding (<1.11.42)GHSA-x6gc-5g5m-hm3r published
Aug 30, 2026 by ywarnierHigh -
Missing Source-Course Authorization in Course Maintenance Copy Endpoints (<2.0.3)GHSA-7g97-jh3w-53wh published
Aug 4, 2026 by ywarnierModerate -
Unauthenticated Template Creation via /template/document-templates/create (<2.0.3)GHSA-hg2v-955j-35c3 published
Aug 4, 2026 by ywarnierModerate -
Unauthenticated Template Deletion (<2.0.3)GHSA-37fh-r78h-9vvr published
Aug 4, 2026 by ywarnierHigh -
Unauthenticated Disclosure of Private Course Template Content (< 2.0.3)GHSA-9r7v-p62p-h9gc published
Aug 4, 2026 by ywarnierHigh -
Unrestricted switch_user impersonation (< 2.0.3)GHSA-35wp-xr4v-jg99 published
Aug 4, 2026 by ywarnierCritical -
Self-registration role mass-assignment (< 1.11.40, < 2.0.3)GHSA-3v23-qp3p-p2xf published
Aug 4, 2026 by ywarnierHigh -
Path traversal + arbitrary file write via sub-language admin panel (< 2.0.3)GHSA-rpp3-vpc9-w3h2 published
Aug 4, 2026 by ywarnierCritical -
Authenticated path traversal in FileManagerController download endpoint allows arbitrary file read (< 2.0.3)GHSA-7jqm-3829-36cm published
Aug 4, 2026 by ywarnierHigh