Stored Cross-Site Scripting in Chamilo LMS by Chamilo Association
CVE-2026-39878

9.3CRITICAL

Key Information:

Vendor

Chamilo

Vendor
CVE Published:
20 July 2026

What is CVE-2026-39878?

The Chamilo LMS, specifically versions 1.11.38 and prior, is susceptible to a stored cross-site scripting vulnerability within its user registration feature. This flaw permits an unauthenticated attacker to inject and execute arbitrary JavaScript code within an administrator's browser session, potentially leading to full administrative control over the platform. The vulnerability has been addressed and resolved in version 1.11.40, emphasizing the importance of updating to the latest release to safeguard against such threats.

Affected Version(s)

chamilo-lms <= 1.11.38

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.