These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE-2026-72610 vulnerability is a stored SQL injection issue in Koha, a library management system. This vulnerability allows authenticated staff with borrowers => edit_borrowers permission to cause a time-based denial of service by storing a SQL payload in a patron lang field. The payload executes on each subsequent issue-slip print, potentially causing performance impacts. The vulnerability affects K [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:44.120Z and has not been modified since then. The CVE-2026-72609 vulnerability is an SQL injection issue in Koha versions through 24.11.17, 25.05.12, 25.11.06, and 26.05.01. Authenticated staff with the acquisition => order_receive permission can exploit this vulnerability to read arbitrary [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:43.987Z and has not been modified since then. CVE-2026-72608 describes a stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01. Authenticated staff with the tools => label_creator permission can execute arbitrary SQL via the image_name field of a patr [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:43.867Z and has not been modified since then. This stored SQL injection vulnerability in Koha allows authenticated staff with specific permissions to read arbitrary database contents. The vulnerability arises from the agefield value of an automatic item modification rule being stored verbat [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T13:24:53.583Z and has not been modified since then. CVE-2026-71288 is a SQL injection vulnerability in Koha's guided report builder feature. The vulnerability allows low-privilege staff accounts with create_reports or execute_reports permissions to perform time-based blind SQL injection against t [truncated]
The CVE-2026-70373 vulnerability affects Koha, an open-source integrated library system. The vulnerability class is SQL injection, which allows an authenticated staff user with reports module permission to inject arbitrary SQL and potentially read any table accessible by the Koha database user. The likely operational impact is unauthorized access to sensitive information such as borrower data, API keys, a [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T13:18:58.040Z and has not been modified since then. Koha's reports/bor_issues_top.pl is vulnerable to SQL injection. An authenticated staff user with reports module permissions can inject arbitrary SQL by manipulating request parameters, allowing access to sensitive data such as borrowers, api_ke [truncated]
Koha's reports/issues_avg_stats.pl is vulnerable to SQL injection due to user-controlled request parameters being concatenated directly into the query string without validation or parameterization. This allows an authenticated staff user with reports module permission to inject arbitrary SQL and potentially read sensitive data from tables accessible by the Koha database user. The vulnerability can be miti [truncated]
Koha's reports/catalogue_stats.pl is vulnerable to SQL injection due to user-controlled input being directly interpolated into SQL queries without whitelist validation. An authenticated staff user with reports module permission can inject arbitrary SQL and read any table accessible by the Koha database user. This vulnerability affects Koha users and administrators, especially those with reports module per [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T13:18:57.680Z and has not been modified since then. The reports/acquisitions_stats.pl script in Koha interpolates user-controlled Filter request parameters directly into WHERE fragments of a SQL query without bound parameters. This allows an authenticated staff user with reports module permission [truncated]
CVE-2026-6428 is a SQL injection vulnerability in Koha Community Koha through various versions. An authenticated staff user with the Reports module flag can use the Filter URL parameter in reports/catalogue_out.pl to read arbitrary data from the Koha application database when the Criteria parameter matches /branchcode/. The vulnerability is due to the vulnerable sink in sub calculate concatenating the unm [truncated]
CVE-2026-31844 is an authenticated SQL Injection vulnerability in the Koha staff interface, specifically in the /cgi-bin/koha/suggestion/suggestion.pl endpoint. The vulnerability is caused by improper validation of the displayby parameter used by the GetDistinctValues functionality. Successful exploitation may lead to full compromise of the backend database, including disclosure or modification of stored [truncated]