CVE-2026-3007

· NIST NVD ↗

Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.

MEDIUM
CVSS severity
5.4
CVSS base score
2026-04-23
Published

CWE codes

CWE-79

Sources