Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-39878: Chamilo LMS versions 1.11.38 and earlier allow attackers to take control of admin accounts.

CVE-2026-39878 CVE-2026-39878
Summary

Chamilo Learning Management System versions 1.11.38 and earlier have a security flaw in the user registration form. This means an attacker can trick an administrator into running malicious code in their browser, giving the attacker full control over the platform. Update to version 1.11.40 or later to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
chamilo chamilo-lms <= 1.11.38
Original title
Chamilo stored XSS via user registration leads to admin account takeover
Original description
Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full platform admin account takeover. This has been patched in 1.11.40.
nvd CVSS3.1 9.3
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026