CVE-2026-32893 - Chamilo LMS has Reflected XSS via Unsanitized http_build_query() in Exercise Question List Pagination
CVE ID :CVE-2026-32893
Published : April 10, 2026, 5:42 p.m. | 24 minutes ago
Description :Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting ...
Related Vulnerabilities
- CVE-2025-58920: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i HIGH
- CVE-2026-33737: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use sim MEDIUM
- CVE-2026-33707: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password r CRITICAL
- CVE-2026-32892: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a CRITICAL
- CVE-2026-33618: Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController HIGH
Related Coverage
Threat Actors