CVE-2026-31940
High Severity
Description
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to s...
Related Vulnerabilities
- CVE-2026-40175: Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain CRITICAL
- CVE-2026-4149: Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerabil CRITICAL
- CVE-2026-6067: A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds HIGH
- CVE-2026-4664: The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in MEDIUM
- CVE-2026-3371: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure MEDIUM
Related Coverage
Threat Actors