CVE-2026-39878 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
July 21, 2026
Last Seen
July 21, 2026

CVE-2026-39878 is a vulnerability tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed July 21, 2026; most recent activity July 21, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • CVE-2026-39878 - Chamilo stored XSS via user registration leads to admin account takeover Latest Vulnerabilities / 16h CVE ID : CVE-2026-39878 Published : July 20, 2026, 6:16 p.m. 39 minutes ago Description : Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full platform admin account takeover. This ha — cvefeed.io · July 21, 2026
  • Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover ThreatCluster - Threat Intelligence Feed / 24min Key Points: • CVE-2026-39878 allows unauthenticated attackers to take over admin accounts in Chamilo LMS. • The vulnerability affects Chamilo LMS versions 1.11.38 and earlier, with a CVSS score of 9.3. — threatcluster.io · July 21, 2026
  • CVE-2026-39878 - Exploits & Severity — Feedly · July 21, 2026

CVSS v3.1 Breakdown