chamilo has 4 CVEs on record between 2021 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.5 (high), with 2 rated critical. The most common weakness class is CWE-79 (3). Most affected products: chamilo-lms (3), chamilo (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-45140Critical· 9.8Chamilo LMS is an open-source learning management system66CVE-2026-45143Critical· 9.0Chamilo LMS is an open-source learning management system50CVE-2026-82535Medium· 6.1Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php34CVE-2021-43687Medium· 6.1chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.34
chamilo vulnerabilities
CVEs affecting chamilo, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-45143Critical· 9.0Chamilo LMS is an open-source learning management system
Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in assets/vue/views/message/MessageShow.vue a…
CVE-2026-45140Critical· 9.8PoCChamilo LMS is an open-source learning management system
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …
CVE-2026-82535Medium· 6.1Chamilo LMS Stored XSS via Survey Answer Submission in reporting.php
Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypas…
CVE-2021-43687Medium· 6.1chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.
chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.