Vulnerability in Koollab Learning Management System (LMS)
23 April 2026
CSA has issued a CVE ID to a vulnerability reported in Koollab LMS as part of CSA’s Responsibility Vulnerability Disclosure Policy. Users and administrators of the affected product version are advised to update to the latest version 5.4.0 immediately.
Background
CSA has issued a CVE ID (CVE-2026-3007) to a vulnerability reported in Koollab LMS. The Product Owner, Three Learning, an e-learning service provider, has released a security update to address it.
Impact
Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet feature.
Affected Products
The vulnerability affects Koollab LMS version 5.3.2.
Mitigation
Users and administrators of the affected product version are advised to update to the latest version 5.4.0 immediately.
Special Thanks to:
Informer: Mr Justin Ng, CSA
Product Owner: Three Learning
