Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full platform admin account takeover. This has been patched in 1.11.40.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
NVD published the first details for CVE-2026-39878
A CVSS base score of 9.3 has been assigned.
Feedly found the first article mentioning CVE-2026-39878 . See article
Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover
CVE-2026-39878 - Exploits & Severity - Feedly
CVE-2026-39878 - Chamilo stored XSS via user registration leads to admin account takeover
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
