CVE-2026-33737: Chamilo LMS has an XML External Entity (XXE) Injection
Published Apr 10, 2026
·Updated
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexmlloadstring() without XXE protection. With LIBXMLNOENT flag, arbitrary server files can be read. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.
Affected Software
12 affected components
Chamilo Chamilo LMS<1.11.38, <2.0.0-RC.3
Chamilo Chamilo LMS<1.11.38
Chamilo Chamilo LMS=2.0.0-alpha1
Chamilo Chamilo LMS=2.0.0-alpha2
Chamilo Chamilo LMS=2.0.0-alpha3
Chamilo Chamilo LMS=2.0.0-alpha4
Chamilo Chamilo LMS=2.0.0-alpha5
Chamilo Chamilo LMS=2.0.0-beta1
Chamilo Chamilo LMS=2.0.0-beta2
Chamilo Chamilo LMS=2.0.0-beta3
Chamilo Chamilo LMS=2.0.0-rc1
Chamilo Chamilo LMS=2.0.0-rc2
Remediation
Event History
Apr 10, 2026
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-33737?
The severity of CVE-2026-33737 is classified as critical due to the potential for arbitrary file reading on the server.
2
How do I fix CVE-2026-33737?
To fix CVE-2026-33737, upgrade Chamilo LMS to version 1.11.38 or 2.0.0-RC.3 or later.
3
What types of systems are vulnerable to CVE-2026-33737?
Systems running Chamilo LMS versions prior to 1.11.38 or 2.0.0-RC.3 are vulnerable to CVE-2026-33737.
4
Can CVE-2026-33737 lead to data leakage?
Yes, CVE-2026-33737 can lead to data leakage as it allows reading of arbitrary server files.
5
What is the nature of the vulnerability in CVE-2026-33737?
CVE-2026-33737 is an XML External Entity (XXE) Injection vulnerability affecting Chamilo LMS.