
CVE-2026-48909-Joomla-SP-Exploit
CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator

CVE-2023–4220 Exploit

Automated proof-of-concept exploit for CVE-2023-4220 in Chamilo LMS, enabling arbitrary file upload and remote code execution via unauthenticated…

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

Python exploit for CVE-2023-45878 targeting Gibbon LMS 25.0.1. Uses arbitrary file write to upload a PHP web shell and execute a PowerShell reverse…

Shell-based exploit for CVE-2023-4220 targeting unrestricted file upload in Chamilo LMS. Uploads arbitrary files to execute reverse shells on…

Refurbish Chamilo LMS CVE-2023-4220 exploit written in bash