CVE-2026-3007

Published Apr 23, 2026

Last updated 6 days ago

Overview

Description
Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.
Source
5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.4
Impact score
2.7
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.