All verified exploits

CVE-2026-28430 AJAX custom_dates SQL Injection

Deterministic critical Chamilo Added cve-verified-cve-2026-28430

Detects error-based SQL injection in Chamilo LMS via the custom_dates filter property in the model.ajax.php jqGrid endpoint. The endpoint appends user-supplied JSON filter data directly into a SQL WHERE clause without sanitization, allowing unauthenticated database access.

Is your app exploitable through CVE-2026-28430?

Scan your domain free