CVE-2026-33704 - Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint
CVE ID :CVE-2026-33704
Published : April 10, 2026, 7:16 p.m. | 50 minutes ago
Description :Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including st...
Related Vulnerabilities
- CVE-2026-33736: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including MEDIUM
- CVE-2026-33457: Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allo MEDIUM
- CVE-2026-40168: Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vu HIGH
- CVE-2026-40162: Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability wa HIGH
- CVE-2026-33455: Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attac MEDIUM
Related Coverage
Threat Actors