CVE-2025-55208Disclosure(chamilo / chamilo_lms)

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch chamilo chamilo_lms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, a low-privilege user can execute arbitrary code in the admin user inbox, allowing takeover of the admin account. Version 1.11.34 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-07); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 2Mentions · 2026-03-10: 1Mentions · 2026-03-17: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-10: 103-0503-0603-0703-1003-17
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-051
Patch1
2026-03-061
Disclosure1
2026-03-072
Disclosure2
2026-03-101
Disclosure1
2026-03-171
Disclosure1
Full discourse6 posts
  • Dishant Singh@dishant_singh14
    Disclosure

    🚨 Excited to share that I’ve been assigned 2 CVEs: • CVE-2025-55208 (9.0 Critical) • CVE-2025-55289 (8.8 High) Discovered vulnerabilities affecting Chamilo LMS . Grateful for the recognition 🙌 More technical details coming soon. #cybersecurity #bugbounty #infosec #CVE

    Post summary

    The author announces having discovered two critical CVEs affecting Chamilo LMS and promises to release more technical details soon, but provides no exploitation or mitigation information.

    00050525
    413 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-55208: CRITICAL] Chamilo learning management system <1.11.34 is vulnerable to Stored XSS via file uploads in `Social Networks`, fix available in version 1.11.34. Secure your admin account.#cve,CVE-2025-55208,#cybersecurity https://cvefind.com/CVE-2025-55208

    Post summary

    Chamilo LMS versions below 1.11.34 are vulnerable to a stored XSS attack via file uploads in the Social Networks module, but a fix is available in v1.11.34. Users should update to secure their admin accounts.

    1002082
    596 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Chamilo LMS, Stored XSS, #CVE-2025-55208 (High) https://dailycve.com/chamilo-lms-stored-xss-cve-2025-55208-high/

    Post summary

    The post announces a new high‑severity Stored XSS flaw (CVE‑2025‑55208) affecting Chamilo LMS, providing only basic technical details and a link for further information.

    0000060
    166 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-55208 Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, a low-privilege u… https://www.cve.org/CVERecord?id=CVE-2025-55208

    Post summary

    The CVE describes a stored XSS vulnerability in Chamilo versions before 1.11.34 caused by insecure file uploads; no PoC, exploit, patch, or active exploitation details are provided.

    00000239
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-55208 - Critical Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, a low-privilege user can execute arbit... https://www.thehackerwire.com/vulnerability/CVE-2025-55208/ https://t.co/mFTwmaLjAO

    Post summary

    The tweet announces CVE‑2025‑55208, detailing a stored XSS via insecure file uploads in Chamilo versions before 1.11.34, without evidence of exploitation, patches, or a PoC.

    00000194
    128 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-55208 Stored XSS in Chamilo Learning Management System Enables Admin Account Takeover https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-55208

    Post summary

    The text announces a stored XSS vulnerability in Chamilo Learning Management System that can lead to admin account takeover, without providing any PoC, exploit, or patch information.

    0000093
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more