CVE-2026-3007

MEDIUM

Three Learning Koollab Learning Management System < 5.3.2. - XSS

Title source: rule

Description

Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.

Scores

CVSS v3 5.4
EPSS 0.0003
EPSS Percentile 7.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

Status published
Products (1)
Three Learning/Koollab Learning Management System 5.3.2.
Published Apr 23, 2026
Tracked Since Apr 23, 2026