CVE-2026-63227: An Unrestricted Scorm File Upload Vulnerability In Koollab Lms Allowed An Authenticated Module Designer To Upload A Scorm Package Containing A PHP Webshell To A Publicly Accessible Directory And Execute Arbitrary Code On The Server Koollab Lms

Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.

Affected products

Published 2026-07-29. Last modified 2026-07-30.