Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Three Learning — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting Three Learning. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates known security vulnerabilities associated with the software vendor Three Learning, focusing on Common Weakness Enumerations (CWE) and associated Common Vulnerabilities and Exposures (CVEs). The collection compiles historical security data ranging from the vendor's inception to the present, capturing all publicly disclosed issues that have impacted their product ecosystem. By centralizing this information, the page allows security professionals and system administrators to track a vendor's advisory history in one place, understand the specific nature and severity of a weakness class across different versions, and look up a product's vulnerability history to assess long-term maintenance quality. Three Learning provides educational software solutions, and like many vendors in the EdTech sector, its products have been subject to various security flaws ranging from injection attacks to insecure default configurations. This resource serves as a neutral reference point for evaluating the security posture of Three Learning’s offerings without bias. It is designed to facilitate risk assessment, patch management prioritization, and compliance audits by providing a comprehensive view of past vulnerabilities. Users can correlate specific weakness types with product updates to determine if previous flaws have been adequately remediated. The data is sourced from public advisories and vulnerability databases to ensure accuracy and completeness. This structured overview helps organizations make informed decisions regarding the deployment and ongoing security monitoring of Three Learning software within their environments.

CVE IDTitleCVSSSeverityPublished
CVE-2026-63242 Business logic vulnerability — Koollab LMS 4.3 Medium2026-07-29
CVE-2026-63241 Insecure direct object reference vulnerability — Koollab LMS 3.1 Low2026-07-29
CVE-2026-63240 Information disclosure vulnerability — Koollab LMS 4.3 Medium2026-07-29
CVE-2026-63239 Hard-coded AWS IAM credentials vulnerability — Koollab LMS 5.4 Medium2026-07-29
CVE-2026-63238 Authentication bypass vulnerability — Koollab LMS 6.5 Medium2026-07-29
CVE-2026-63237 TOTP two-factor authentication bypass vulnerability — Koollab LMS 4.8 Medium2026-07-29
CVE-2026-63236 Improper access control vulnerability — Koollab LMS 3.7 Low2026-07-29
CVE-2026-63235 Improper access control vulnerability — Koollab LMS 3.7 Low2026-07-29
CVE-2026-63234 SQL injection and unsafe deserialisation vulnerability — Koollab LMS 9.9 Critical2026-07-29
CVE-2026-63233 SQL injection and unsafe deserialisation vulnerability — Koollab LMS 9.9 Critical2026-07-29
CVE-2026-63232 SQL injection and unsafe deserialisation vulnerability — Koollab LMS 9.9 Critical2026-07-29
CVE-2026-63231 Post-authentication SQL injection vulnerability — Koollab LMS 8.1 High2026-07-29
CVE-2026-63230 Pre-authentication error-based SQL injection vulnerability — Koollab LMS 9.1 Critical2026-07-29
CVE-2026-63229 Pre-authentication blind SQL injection vulnerability — Koollab LMS 9.1 Critical2026-07-29
CVE-2026-63228 Unrestricted image upload vulnerability — Koollab LMS 2.6 Low2026-07-29
CVE-2026-3007 Stored Cross-Site Scripting (XSS) Vulnerability — Koollab Learning Management System 5.4 Medium2026-04-23

This page lists every published CVE security advisory associated with Three Learning. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.