CVE-2026-63227
CRITICAL
NVD
CVSS Score
9.9
Severity
CRITICAL
Published
Jul 29, 2026
Vendor
unknown
Description
An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.