composer›chamilo/chamilo-lms›CVE-2026-451409.8 CRITICALChamilo LMS CStudio upload flow allows unauthenticated remote code executionAbility to run arbitrary code on the server without authentication.