CVE-2026-33737 - Chamilo LMS has an XML External Entity (XXE) Injection
CVE ID :CVE-2026-33737
Published : April 10, 2026, 7:16 p.m. | 4 hours, 52 minutes ago
Description :Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple fil...
Related Vulnerabilities
- CVE-2026-34478: Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424L MEDIUM
- CVE-2026-35655: OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution t MEDIUM
- CVE-2026-6026: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability aff CRITICAL
- CVE-2026-6006: A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted e MEDIUM
- CVE-2026-33457: Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allo MEDIUM
Related Coverage
Threat Actors