
CVE-2026-33737 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT fla… https://www.cve.org/CVERecord?id=CVE-2026-33737
Post summary
The entry references an XXE flaw in Chamilo LMS due to unchecked simplexml_load_string() usage, noting that versions 1.11.38 and 2.0.0‑RC.3 onward address the issue.

