CVE-2025-55289Disclosure(chamilo / chamilo_lms)

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch chamilo chamilo_lms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an attacker to inject arbitrary JavaScript into the platform’s social network and internal messaging features. When viewed by an authenticated user (including administrators), the payload executes in their browser within the LMS context. This enables full account takeover via session hijacking, unauthorized actions with the victim’s privileges, exfiltration of sensitive data, and potential self-propagation to other users. This issue has been patched in version 1.11.34.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chamilo_lms

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-06); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
chamilo_lms

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-06: 3Mentions · 2026-03-11: 1Mentions · 2026-03-17: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-06: 3Technical Details · 2026-03-11: 1Technical Details · 2026-03-17: 103-0603-1103-17
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-063
Disclosure2Patch1
2026-03-111
Disclosure1
2026-03-171
Disclosure1
Full discourse5 posts
  • Dishant Singh@dishant_singh14
    Disclosure

    🚨 Excited to share that I’ve been assigned 2 CVEs: • CVE-2025-55208 (9.0 Critical) • CVE-2025-55289 (8.8 High) Discovered vulnerabilities affecting Chamilo LMS . Grateful for the recognition 🙌 More technical details coming soon. #cybersecurity #bugbounty #infosec #CVE

    Post summary

    The tweet announces the discovery of two new critical and high‑severity CVEs affecting Chamilo LMS, promising further technical details to follow.

    00050525
    413 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-55289 (CVSS:8.8, HIGH) is Analyzed. Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (V..https://nvd.nist.gov/vuln/detail/CVE-2025-55289 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post discloses a stored XSS flaw in Chamilo LMS with CVSS 8.8, affecting versions before 1.11.34, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0101163
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-55289 Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an attacker to inject a… https://www.cve.org/CVERecord?id=CVE-2025-55289

    Post summary

    The post discloses a stored XSS vulnerability in Chamilo LMS before version 1.11.34, referencing the CVE.

    00000166
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-55289 - High Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an attacker to inject arbitrary JavaScript into ... https://www.thehackerwire.com/vulnerability/CVE-2025-55289/ https://t.co/Nzd59mozgc

    Post summary

    Chamilo LMS versions prior to 1.11.34 suffer from a stored XSS flaw (CVE‑2025‑55289) that permits arbitrary JavaScript injection.

    0000093
    125 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2025-55289: HIGH] Chamilo LMS v1.11.32 had a stored XSS vulnerability allowing attackers to inject malicious code, now fixed in v1.11.34. Important to update for cybersecurity.#cve,CVE-2025-55289,#cybersecurity https://cvefind.com/CVE-2025-55289

    Post summary

    The post highlights a stored XSS flaw in Chamilo LMS v1.11.32, notes it is fixed in v1.11.34, and advises users to update their systems.

    0000076
    597 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchamilochamilo_lms---

Explore more