39878 Critical · 9.3
CVE-2026-39878 — Unauthenticated Stored XSS to Admin Takeover in Chamilo LMS
A stored XSS (CWE-79) in Chamilo's self-registration form. A null byte hidden inside an event handler defeats HTMLPurifier, and the admin user list renders the stored name without escaping — firing the payload in an administrator's session and enabling full platform admin takeover. CVSS 9.3 Critical. Found by Voke Cyber, fixed in 1.11.40.