CVE-2025-50187
critical · 9.8Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has been patched in version 1.11.28.
9.8
CVSS
0.9%
EPSS (exploit prob.)
58th
EPSS percentile
2026-03-02
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-95
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| chamilo | chamilo_lms | < 1.11.28 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-50187