Known Vulnerabilities for products from Koha

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Koha".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-50767 json A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 th... Not Provided 2026-06-26 2026-07-05
CVE-2026-50766 json A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25... Not Provided 2026-06-26 2026-07-05
CVE-2026-50765 json A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Manageme... Not Provided 2026-06-26 2026-07-05
CVE-2026-31844 json An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/sugg... Not Provided 2026-03-11 2026-05-07
CVE-2026-26379 json Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration.... Not Provided 2026-06-03 2026-07-22
CVE-2026-26378 json Not Provided 2026-06-03 2026-06-04
CVE-2026-6428 json Not Provided 2026-06-13 2026-06-15
CVE-2023-5025 json A vulnerability was found in KOHA up to 23.05.03. It has been declared as problematic. This vulnerability affects unknown cod... 5.4 - MEDIUM 2023-09-17 2023-11-07
CVE-2022-0495 json Not Provided 2022-09-21 2026-05-20
CVE-2018-1000670 json KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS)... 6.1 - MEDIUM 2018-09-06 2018-11-07
CVE-2018-1000669 json KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery... 8.8 - HIGH 2018-09-06 2018-11-07
CVE-2015-4639 json Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, a... Not Provided 2017-07-21 2025-04-20
CVE-2015-4633 json Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.... 9.8 - CRITICAL 2018-10-18 2018-12-06
CVE-2015-4632 json Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and... 7.5 - HIGH 2018-10-18 2018-12-31
CVE-2015-4631 json Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.... 5.4 - MEDIUM 2018-10-18 2018-12-04
CVE-2015-4630 json Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x befor... 8 - HIGH 2018-10-18 2018-12-04
CVE-2014-9446 json Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow ... Not Provided 2015-01-02 2026-05-06
CVE-2014-1925 json SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.... 9.8 - CRITICAL 2020-01-24 2020-01-30
CVE-2014-1924 json The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.... 9.8 - CRITICAL 2020-01-24 2020-01-30
CVE-2014-1923 json Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl ... 7.5 - HIGH 2020-01-24 2020-01-30

Known software with vulnerabilities from Koha

Type Vendor Product Version
ApplicationKohaKoha16.05.00

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report