CVE-2026-19780 debrief based on the supplied source corpus. The vulnerability exists within the web service, which listens on TCP port 8081 by default. The issue results from the lack of proper validation of a user-supplied string before passing it to the eval function. This allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vuln [truncated]
CVE-2026-50767 is a stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System through 25.11. An authenticated remote attacker with administrator privileges can inject arbitrary web scripts via the item type check-in message field (checkinmsg). The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. The CVE was published on 2026-06-26 [truncated]