Products: 3
    Vulnerabilities: 28
    Known Exploited: 0
    5
    Critical Level Threats
    11
    High Level Threats
    11
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-50767

    Stored XSS in Koha Item Type Administration Page

    Last Modified: Jul 05, 2026
    Published: Jun 26, 2026

    CVE-2026-50766

    A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field (items.itemnotes).

    Last Modified: Jul 05, 2026
    Published: Jun 26, 2026

    CVE-2026-50765

    Stored XSS in Koha Patron Restriction Type Administration Page

    Last Modified: Jul 05, 2026
    Published: Jun 26, 2026

    CVE-2026-26379

    Koha SSRF via Z39.50 Configuration Enables Internal Network Scanning

    Last Modified: Jun 04, 2026
    Published: Jun 03, 2026

    CVE-2026-26378

    Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice features

    Last Modified: Jun 04, 2026
    Published: Jun 03, 2026
    Items Per Page
    Koha Vulnerabilities & Security CVEs | CVE-DB