CVE-2025-52482Disclosure(chamilo / chamilo_lms)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch chamilo chamilo_lms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 8 classified signals
  • Peaked 5d ago at 4 mentions (2026-03-02); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline9 mentions / 6d
01234Mentions · 2026-03-02: 4Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Mentions · 2026-03-16: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-02: 4Technical Details · 2026-03-03: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-16: 103-0203-0303-0503-0603-0703-16
Signal classification2 categories
Disclosure
888.9%
Patch
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-024
Disclosure4
2026-03-031
Patch1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-03-071
Disclosure1
2026-03-161
Disclosure1
Full discourse9 posts
  • BrHackeuses@BrHackeuses
    Disclosure

    🚨 New CVE discovered by Elyse from @BrHackeuses CVE-2025-52482 – Stored XSS in Chamilo LMS glossary A Teacher could inject JavaScript executed in the admin interface Patch: https://github.com/chamilo/chamilo-lms/commit/241c569dde0ad0e34d558ae51271f70438189b0e Great to see women contributing to vulnerability research💜 #BrHackeuses https://t.co/L12wTh7PzU

    Post summary

    Elyse from BrHackeuses announces CVE-2025-52482, a stored XSS vulnerability in Chamilo LMS, and provides a patch link for remediation.

    10010114
    119 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-52482 (CVSS:8.3, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary fun..https://nvd.nist.gov/vuln/detail/CVE-2025-52482 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a Stored XSS vulnerability (CVE‑2025‑52482) in Chamilo before version 1.11.30 with a CVSS score of 8.3, but it offers no PoC, exploitation details, or patch information.

    00000105
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-52482 (CVSS:8.3, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary fun..https://nvd.nist.gov/vuln/detail/CVE-2025-52482 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces that CVE‑2025‑52482 is a high‑severity stored XSS vulnerability in Chamilo’s glossary functionality prior to version 1.11.30, with a reference to the NVD entry.

    0000041
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-52482 (CVSS:8.3, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary fun..https://nvd.nist.gov/vuln/detail/CVE-2025-52482 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2025-52482, detailing it as a Stored XSS vulnerability in Chamilo with CVSS 8.3, but provides no proof‑of‑concept, exploit, or patch information.

    0000034
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A stored #XSS vulnerability, CVE-2025-52482, affects `Chamilo` LMS. Malicious scripts can be injected via the glossary function, impacting user sessions. Review advisories for patch details. #infosec #LMS https://www.pulsepatch.io/posts/cve-2025-52482-chamilo-stored-xss

    Post summary

    The post announces a stored XSS vulnerability (CVE‑2025‑52482) in Chamilo LMS and directs readers to advisories for patch details.

    0000087
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-52482 Stored XSS in Chamilo LMS Glossary Function Allows Teacher-Initiated Attacks https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-52482

    Post summary

    A stored XSS vulnerability (CVE‑2025‑52482) in Chamilo LMS’s Glossary function enables teachers to initiate attacks.

    0000076
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-52482 Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers ro… https://www.cve.org/CVERecord?id=CVE-2025-52482 ----- Traducción: CVE-2025-52482 Cha… http://infoflow.cloud`

    Post summary

    The post announces a stored XSS vulnerability in Chamilo's glossary function that affects users with teacher roles, prior to version 1.11.30.

    0000094
    55 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-52482 - High Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript m... https://www.thehackerwire.com/vulnerability/CVE-2025-52482/ https://t.co/HJVlSy0bAD

    Post summary

    The post discloses a stored XSS vulnerability in Chamilo’s glossary function that allows teachers to inject JavaScript, providing technical details but no PoC, exploit, or patch information.

    00000112
    122 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-52482 Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers ro… https://www.cve.org/CVERecord?id=CVE-2025-52482

    Post summary

    CVE-2025-52482 reveals a stored XSS flaw in Chamilo’s glossary function that impacts teacher users prior to version 1.11.30.

    00000189
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more