Chamilo LMS is a technology platform tracked across 2 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed April 11, 2026; most recent activity July 21, 2026.
A critical stored cross-site scripting vulnerability, CVE-2026-39878, was discovered in Chamilo LMS versions 1.11.38 and earlier. This flaw allows unauthenticated attackers to execute arbitrary JavaScript in an…
CVE-2026-33707 is a critical vulnerability affecting Chamilo LMS versions prior to 1.11.38 and 2.0.0-RC.3. The flaw arises from a weak password reset mechanism that generates predictable tokens using sha1($email)…