CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-63228

lowCVSS 2.6covered by 1 sourcefirst seen 2026-07-29
An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the server.

⚡ Watch CVE-2026-63228

Get an email if CVE-2026-63228 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-63228

CVE.org record

Embed the live status

CVE-2026-63228 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-63228 status](https://www.csirts.com/badge/CVE-2026-63228)](https://www.csirts.com/cve/CVE-2026-63228)