---
id: CVE-2026-39878
title: >-
  Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting
  vulnerability in the user registration form that allows any unauthenticated
  attacker to execute arbitrary JavaScript in an administrator's browser
  session, le…
summary: >-
  Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting
  vulnerability in the user registration form that allows any unauthenticated
  attacker to execute arbitrary JavaScript in an administrator's browser
  session, le…
severity: critical
cvss: 9.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
published: '2026-07-20'
updated: '2026-08-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39878'
references:
  - url: >-
      https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-gcjp-f7jm-rrrg
    label: security-advisories@github.com
  - url: 'https://vokecyber.com/research/cve-2026-39878-chamilo-lms-stored-xss'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00435
epssPercentile: 0.35131
ingestedAt: '2026-08-22T13:32:35.527Z'
---

## Overview

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full platform admin account takeover. This has been patched in 1.11.40.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
