VYPR

KOHA Library System

by Koha

CVEs (7)

  • CVE-2024-36058CriApr 7, 2026
    risk 0.64cvss 9.8epss 0.00

    The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database.

  • CVE-2024-36057CriApr 7, 2026
    risk 0.64cvss 9.8epss 0.02

    Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $filename -d $dirname/;" in upload-cover-image.pl is vulnerable to command injection via shell metacharacters because input data…

  • CVE-2018-1000669HigSep 6, 2018
    risk 0.57cvss 8.8epss 0.00

    KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnerability in /cgi-bin/koha/members/paycollect.pl Parameters affected: borrowernumber, amount, amountoutstanding, paid that can result in…

  • CVE-2024-24337HigFeb 12, 2024
    risk 0.52cvss 8.0epss 0.01

    CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.

  • CVE-2026-50767MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the item type check-in…

  • CVE-2026-50766MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field…

  • CVE-2026-50765MedJun 26, 2026
    risk 0.00cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the…