CVE-2026-33704 - Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint
CVE ID :CVE-2026-33704
Published : April 10, 2026, 7:16 p.m. | 50 minutes ago
Description :Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including st...
Related Vulnerabilities
- CVE-2026-40168: Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vu HIGH
- CVE-2026-40191: ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. N/A
- CVE-2026-35641: OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hoo HIGH
- CVE-2026-30232: Chartbrew is an open-source web application that can connect directly to databases and APIs and use N/A
- CVE-2026-6035: A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected MEDIUM
Related Coverage
Threat Actors