CVE-2025-66447 - Chamilo LMS has validation-less redirect on login page
CVE ID :CVE-2025-66447
Published : April 10, 2026, 5:22 p.m. | 44 minutes ago
Description :Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malici...
Related Vulnerabilities
- CVE-2026-22560: An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected MEDIUM
- CVE-2026-40160: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path pas HIGH
- CVE-2026-33704: Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including stu HIGH
- CVE-2026-32930: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-40074: @sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service MEDIUM
Related Coverage
Threat Actors