CVE-2024-36058
- EPSS 0.05%
- Veröffentlicht 07.04.2026 00:00:00
- Zuletzt bearbeitet 09.04.2026 14:16:24
The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from ...
CVE-2024-36057
- EPSS 0.14%
- Veröffentlicht 07.04.2026 00:00:00
- Zuletzt bearbeitet 09.04.2026 14:16:24
Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $filename -d $dirname/;" in upload-cover-image.pl is vulnerable to command injection via shell metacha...
CVE-2026-26377
- EPSS 0.06%
- Veröffentlicht 05.03.2026 00:00:00
- Zuletzt bearbeitet 10.03.2026 18:18:43
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.
CVE-2025-52360
- EPSS 0.1%
- Veröffentlicht 25.07.2025 15:15:29
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Cross-Site Scripting (XSS) vulnerability exists in the OPAC search feature of Koha Library Management System v24.05. Unsanitized input entered in the search field is reflected in the search history interface, leading to the execution of arbitrary J...
CVE-2025-30076
- EPSS 0.08%
- Veröffentlicht 16.03.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
Koha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.
- EPSS 11.93%
- Veröffentlicht 12.03.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.
CVE-2024-28740
- EPSS 5.64%
- Veröffentlicht 06.08.2024 19:15:56
- Zuletzt bearbeitet 21.08.2024 18:35:02
Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contents.pl component.
CVE-2024-28739
- EPSS 23%
- Veröffentlicht 06.08.2024 19:15:56
- Zuletzt bearbeitet 12.08.2024 18:18:17
An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.
- EPSS 2.97%
- Veröffentlicht 12.02.2024 22:15:08
- Zuletzt bearbeitet 29.09.2025 15:16:05
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Membe...
CVE-2023-5025
- EPSS 0.1%
- Veröffentlicht 17.09.2023 07:15:10
- Zuletzt bearbeitet 21.11.2024 08:40:55
A vulnerability was found in KOHA up to 23.05.03. It has been declared as problematic. This vulnerability affects unknown code of the file /cgi-bin/koha/catalogue/search.pl of the component MARC. The manipulation leads to cross site scripting. The at...