CVE-2026-33737 - Chamilo LMS has an XML External Entity (XXE) Injection
CVE ID :CVE-2026-33737
Published : April 10, 2026, 7:16 p.m. | 4 hours, 52 minutes ago
Description :Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple fil...
Related Vulnerabilities
- CVE-2026-35600: Vikunja has HTML Injection via Task Titles in Overdue Email Notifications MEDIUM
- CVE-2026-32931: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file u HIGH
- CVE-2026-36236: SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php vi CRITICAL
- CVE-2026-23780: An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in HIGH
- CVE-2026-5053: NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability al HIGH
Related Coverage
Threat Actors