Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-39878 — Chamilo stored XSS via user registration leads to admin account takeover

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in …

chamilo_lms | Remote | Cross-Site Scripting
Jul 20, 2026 Jul 22, 2026
Jul 20, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-34239 — Chamilo Authenticated Remote Code Execution

Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`…

chamilo_lms | Remote | Authentication
Jul 20, 2026 Jul 22, 2026
Jul 20, 2026
Jul 22, 2026
6.1 MEDIUM
CVE-2026-26483 — Mettle SendPortal Stored Cross-Site Scripting Vulnerability

Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input…

Remote | Cross-Site Scripting
Jul 20, 2026 Jul 23, 2026
Jul 20, 2026
Jul 23, 2026
Showing 20 of 12463 Results