CVE-2026-3007

MEDIUM

Koollab Learning Management System >=5.3.2 <5.3.2 - Stored Cross-Site Scripting in Courselet Feature

Title source: llm
STIX 2.1

Description

Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.

Scores

CVSS v3 5.4
EPSS 0.0017
EPSS Percentile 6.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
Three Learning/Koollab Learning Management System 5.3.2.
Published Apr 23, 2026
Tracked Since Apr 23, 2026