CVE-2026-32893 - Chamilo LMS has Reflected XSS via Unsanitized http_build_query() in Exercise Question List Pagination
CVE ID :CVE-2026-32893
Published : April 10, 2026, 5:42 p.m. | 24 minutes ago
Description :Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting ...
Related Vulnerabilities
- CVE-2026-4351: The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in HIGH
- CVE-2026-32894: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-33710: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are gene HIGH
- CVE-2025-58920: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i HIGH
- CVE-2026-33737: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use sim MEDIUM
Related Coverage
Threat Actors