Security Research

Vulnerabilities we have found and responsibly disclosed in widely used software. Original research, coordinated disclosure, and the CVEs that come out of it.

CVE-2026-
39878
Critical · 9.3
Chamilo LMS · Stored XSS

CVE-2026-39878 — Unauthenticated Stored XSS to Admin Takeover in Chamilo LMS

A stored XSS (CWE-79) in Chamilo's self-registration form. A null byte hidden inside an event handler defeats HTMLPurifier, and the admin user list renders the stored name without escaping — firing the payload in an administrator's session and enabling full platform admin takeover. CVSS 9.3 Critical. Found by Voke Cyber, fixed in 1.11.40.

More advisories are on the way as findings clear coordinated disclosure.  ·  Vulnerability Disclosure Policy

The same testing, on your software

The manual, by-hand testing that finds bugs like this is exactly what we do for clients across the Charlotte, NC area and nationwide.

Get a Quote