Skip to main content

Vendor archive

koha CVEs

Beta · best-effort

24 CVEs tagged to vendor koha4 Critical, 9 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2026-50767

Published Jun 26, 2026

A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote att…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50766

Published Jun 26, 2026

A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker wi…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50765

Published Jun 26, 2026

A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authentica…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26379

Published Jun 3, 2026

Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform intern…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-26378

Published Jun 3, 2026

Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice features

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-31844

Published Mar 11, 2026

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the d…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-26377

Published Mar 5, 2026

Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2024-28740

Published Aug 6, 2024

Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contents.pl component.

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-28739

Published Aug 6, 2024

An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-24337

Published Feb 12, 2024

CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to i…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5025

Published Sep 17, 2023

A vulnerability was found in KOHA up to 23.05.03. It has been declared as problematic. This vulnerability affects unknown code of the file /cgi-bin/koha/catalogue/search.pl of the…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-1925

Published Jan 24, 2020

SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, an…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-1924

Published Jan 24, 2020

The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 does not…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-1923

Published Jan 24, 2020

Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1922

Published Jan 24, 2020

Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote attackers t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4633

Published Oct 18, 2018

Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-4632

Published Oct 18, 2018

Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4631

Published Oct 18, 2018

Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4630

Published Oct 18, 2018

Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attac…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000670

Published Sep 6, 2018

KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability in Multiple fields on multiple pages in…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000669

Published Sep 6, 2018

KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnerability in /cgi-bin/koha/members/paycoll…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4639

Published Jul 21, 2017

Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 allows remote attackers to inj…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9446

Published Jan 2, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4715

Published Dec 8, 2011

Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows remote attackers to read arbit…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1