Known Vulnerabilities for Koollab LMS by Three Learning
Listed below are 10 of the newest known vulnerabilities associated with "Koollab LMS" by "Three Learning".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63242 json | A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to compl... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-63241 json | An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-63240 json | An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers from t... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-63239 json | A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets an... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-63238 json | An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-63237 json | A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed t... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-63236 json | An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, inte... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-63235 json | An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-63234 json | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through t... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-63233 json | A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through t... | Not Provided | 2026-07-29 | 2026-07-29 |