CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Koha Remove filter Clear all
CVE-2026-19780 HIGH

Koha Eval Code Injection Remote Code Execution Vulnerability

CVSS 8.8 EPSS 0.58% Sep 15, 2026
CVE-2026-50767 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an auth…

CVSS 5.4 EPSS 0.28% Jun 26, 2026
CVE-2026-50766 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticate…

CVSS 5.4 EPSS 0.28% Jun 26, 2026
CVE-2026-50765 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions…

CVSS 6.1 EPSS 0.31% Jun 26, 2026
CVE-2026-26379 MEDIUM

Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attacke…

CVSS 6.5 EPSS 0.37% Jun 3, 2026
CVE-2026-26378 MEDIUM

Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice features

CVSS 5.4 EPSS 0.46% Jun 3, 2026
CVE-2026-31844 HIGH

Authenticated SQL Injection in Koha displayby parameter of suggestion.pl

CVSS 8.7 EPSS 0.57% Mar 11, 2026
CVE-2026-26377 MEDIUM

Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.

CVSS 5.4 EPSS 0.47% Mar 5, 2026
CVE-2025-30076 HIGH

Koha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.

CVSS 7.7 EPSS 0.41% Mar 16, 2025
CVE-2025-22954 CRITICAL

GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.

CVSS 10.0 EPSS 25.55% Mar 12, 2025
CVE-2024-28740 CRITICAL

Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contents.pl component.

CVSS 9.6 EPSS 0.71% Aug 6, 2024
CVE-2024-28739 CRITICAL

An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.

CVSS 9.6 EPSS 18.92% Aug 6, 2024
CVE-2024-24337 HIGH

CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allo…

CVSS 8.8 EPSS 0.81% Feb 12, 2024
CVE-2023-5025 MEDIUM

KOHA MARC search.pl cross site scripting

CVSS 5.4 EPSS 0.61% Sep 17, 2023
CVE-2014-1925 CRITICAL

SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.…

CVSS 9.8 EPSS 1.99% Jan 24, 2020
CVE-2014-1924 CRITICAL

The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x be…

CVSS 9.8 EPSS 2.04% Jan 24, 2020
CVE-2014-1922 HIGH

Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow…

CVSS 7.5 EPSS 2.31% Jan 24, 2020
CVE-2014-1923 HIGH

Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x befo…

CVSS 7.5 EPSS 3.46% Jan 24, 2020
CVE-2015-4633 CRITICAL

Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote a…

CVSS 9.8 EPSS 6.07% Oct 18, 2018
CVE-2015-4632 HIGH

Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote…

CVSS 7.5 EPSS 51.83% Oct 18, 2018
CVE-2015-4631 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow…

CVSS 5.4 EPSS 3.71% Oct 18, 2018
CVE-2015-4630 HIGH

Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.…

CVSS 8.0 EPSS 2.97% Oct 18, 2018
CVE-2018-1000670 MEDIUM

KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability in Multiple fields…

CVSS 6.1 EPSS 0.65% Sep 6, 2018
CVE-2018-1000669 HIGH

KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnerability in /cgi-bin/…

CVSS 8.8 EPSS 0.48% Sep 6, 2018
CVE-2015-4639 HIGH

Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 allows rem…

CVSS 8.8 EPSS 0.62% Jul 21, 2017

Showing 1 to 25 CVEs · page 1 (more available)