CRITICAL 9 CVE-2026-45143 Published 17 Sept 2026

Chamilo LMS Message Injection Vulnerability

Worried this affects your website?

Chamilo LMS, an open-source learning management system, is affected by a stored XSS vulnerability.

From version 2.0.0 to at least 2.1.0, Chamilo LMS stores private messages without server-side sanitization and renders them as HTML.

An authenticated user, including a student, can send a crafted message to an administrator, which will then execute in the recipient's browser when opened, potentially exposing session credentials or allowing actions as the administrator.

This vulnerability is fixed in version 2.0.1.

Reference: CVE-2026-45143 on NVD

← Back to Security News