Koollab LMS Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Koollab Learning Management System (LMS) version 5.3.2. This vulnerability allows an attacker to execute arbitrary JavaScript on any user account that accesses the courselet feature.

Impact

Exploitation of this vulnerability could lead to the execution of malicious JavaScript on behalf of the affected user.

Remediation

Users and administrators are advised to update to Koollab LMS version 5.4.0 immediately.

Added: Apr 23, 2026, 4:22 AM
Updated: Apr 23, 2026, 4:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.0
remediation
0.0
relevance
6.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.