CVE-2026-32893 - Chamilo LMS has Reflected XSS via Unsanitized http_build_query() in Exercise Question List Pagination
CVE ID :CVE-2026-32893
Published : April 10, 2026, 5:42 p.m. | 24 minutes ago
Description :Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting ...
Related Vulnerabilities
- CVE-2026-40225: In udev in systemd before 260, local root execution can occur via malicious hardware devices and uns MEDIUM
- CVE-2026-33710: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are gene HIGH
- CVE-2026-31941: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a HIGH
- CVE-2026-33618: Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController HIGH
- CVE-2026-32893: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting ( MEDIUM
Related Coverage
Threat Actors