
CVE-2026-33705 Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication… https://www.cve.org/CVERecord?id=CVE-2026-33705
Post summary
CVE‑2026‑33705 exposes Chamilo LMS to unauthenticated access of Twig template files prior to version 1.11.38; the vulnerability is mitigated in later releases.

