CVE-2026-3007
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/04/2026
Last modified:
05/05/2026
Description
Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM



