CVE-2026-3007 PUBLISHED

Stored Cross-Site Scripting (XSS) Vulnerability

Assigner: CSA
Reserved: 23.02.2026 Published: 23.04.2026 Updated: 23.04.2026

Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor Three Learning
Product Koollab Learning Management System
Versions Default: unaffected
  • Version 5.3.2. is affected

Solutions

Users and administrators of the affected product version are advised to update to the latest version 5.4.0 immediately.

Credits

  • Justin Ng finder

References