CVE-2026-3007
MEDIUMThree Learning Koollab Learning Management System < 5.3.2. - XSS
Title source: ruleDescription
Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.
Scores
CVSS v3
5.4
EPSS
0.0003
EPSS Percentile
7.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
Status
published
Products (1)
Three Learning/Koollab Learning Management System
5.3.2.
Published
Apr 23, 2026
Tracked Since
Apr 23, 2026