- EPSS -
- Veröffentlicht 26.06.2026 00:00:00
- Zuletzt bearbeitet 26.06.2026 22:16:32
A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System through 25.11 allows an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the item ...
- EPSS -
- Veröffentlicht 26.06.2026 00:00:00
- Zuletzt bearbeitet 26.06.2026 22:16:32
A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System through 25.11 allows an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public note...
- EPSS -
- Veröffentlicht 26.06.2026 00:00:00
- Zuletzt bearbeitet 26.06.2026 22:16:32
Cross-Site Scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System through 25.11 allows an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the ...
CVE-2026-26379
- EPSS 0.24%
- Veröffentlicht 03.06.2026 00:00:00
- Zuletzt bearbeitet 04.06.2026 18:54:11
Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzing server r...
CVE-2026-26378
- EPSS 0.3%
- Veröffentlicht 03.06.2026 00:00:00
- Zuletzt bearbeitet 04.06.2026 18:49:28
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice features
CVE-2024-36058
- EPSS 0.48%
- Veröffentlicht 07.04.2026 00:00:00
- Zuletzt bearbeitet 09.04.2026 14:16:24
The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from ...
CVE-2024-36057
- EPSS 1.8%
- Veröffentlicht 07.04.2026 00:00:00
- Zuletzt bearbeitet 09.04.2026 14:16:24
Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $filename -d $dirname/;" in upload-cover-image.pl is vulnerable to command injection via shell metacha...
- EPSS 0.44%
- Veröffentlicht 11.03.2026 06:34:14
- Zuletzt bearbeitet 07.05.2026 18:27:42
An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. A low-p...
CVE-2026-26377
- EPSS 0.37%
- Veröffentlicht 05.03.2026 00:00:00
- Zuletzt bearbeitet 10.03.2026 18:18:43
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.
CVE-2025-52360
- EPSS 0.49%
- Veröffentlicht 25.07.2025 15:15:29
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Cross-Site Scripting (XSS) vulnerability exists in the OPAC search feature of Koha Library Management System v24.05. Unsanitized input entered in the search field is reflected in the search history interface, leading to the execution of arbitrary J...