CVE-2026-33704 - Chamilo LMS Affected by Authenticated Arbitrary File Write via BigUpload endpoint
CVE ID :CVE-2026-33704
Published : April 10, 2026, 7:16 p.m. | 50 minutes ago
Description :Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including st...
Related Vulnerabilities
- CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison HIGH
- CVE-2026-6005: A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is MEDIUM
- CVE-2026-6057: FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload A CRITICAL
- CVE-2026-31940: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.p HIGH
- CVE-2026-40086: Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the MEDIUM
Related Coverage
Threat Actors