PatchSiren

Koha CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Koha CVE published 2026-09-15

CVE-2026-19780

CVE-2026-19780 debrief based on the supplied source corpus. The vulnerability exists within the web service, which listens on TCP port 8081 by default. The issue results from the lack of proper validation of a user-supplied string before passing it to the eval function. This allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vuln [truncated]

MEDIUM Koha CVE published 2026-06-26

CVE-2026-50767

CVE-2026-50767 is a stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System through 25.11. An authenticated remote attacker with administrator privileges can inject arbitrary web scripts via the item type check-in message field (checkinmsg). The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. The CVE was published on 2026-06-26 [truncated]