Koha vulnerabilities
5 CVEs tracked
Koha appears in our reporting in the context of critical SQL injection across multiple report modules and a stored XSS vulnerability (CVE-2026-41921). The main incidents involve the unsafe concatenation of user-controlled parameters like 'Line', 'Column', and 'order_by' directly into SQL queries in the reports/ scripts (CVE-2026-70370, CVE-2026-70371, CVE-2026-71288), alongside similar unsanitized interpolation of parameters like 'PeriodTypeSel' in circulation statistics (CVE-2026-70373). Defenders should urgently apply the vendor-provided patches and restrict access to these reporting scripts to authenticated staff users only.
Azərbaycanca: Koha bizim hesabatlarda müxtəlif hesabat modullarında ciddi SQL injection və saxlanılmış XSS zəiflikləri (CVE-2026-41921) ilə əlaqədar görünür. Əsas hadisələr `reports/` qovluğundakı skriptlərdə istifadəçidən gələn `Line`, `Column`, `order_by` kimi parametrlərin heç bir yoxlama olmadan birbaşa SQL sorğularına daxil edilməsi ilə bağlıdır (CVE-2026-70370, CVE-2026-70371, CVE-2026-71288), eyni zamanda tiraj statistikası hesabatında `PeriodTypeSel` kimi parametrlər də oxşar risk yaradır (CVE-2026-70373). Müdafiəçi təcili olaraq təchizatçının təqdim etdiyi yeniləmələri tətbiq etməli, həmçinin bu hesabat skriptlərinə girişi autentifikasiya olunmuş istifadəçilərlə məhdudlaşdırmalıdır.
This vendor's CVEs5
This hub is built from skopnix's own reporting on Koha: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.