CVE-2026-3007
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Apr 23, 2026
Vendor
unknown
Description
Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.