PatchSiren

Koha Community CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Koha Community CVE published 2026-08-11

CVE-2026-72610

The CVE-2026-72610 vulnerability is a stored SQL injection issue in Koha, a library management system. This vulnerability allows authenticated staff with borrowers => edit_borrowers permission to cause a time-based denial of service by storing a SQL payload in a patron lang field. The payload executes on each subsequent issue-slip print, potentially causing performance impacts. The vulnerability affects K [truncated]

HIGH Koha Community CVE published 2026-08-11

CVE-2026-72609

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:44.120Z and has not been modified since then. The CVE-2026-72609 vulnerability is an SQL injection issue in Koha versions through 24.11.17, 25.05.12, 25.11.06, and 26.05.01. Authenticated staff with the acquisition => order_receive permission can exploit this vulnerability to read arbitrary [truncated]

MEDIUM Koha Community CVE published 2026-08-11

CVE-2026-72608

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:43.987Z and has not been modified since then. CVE-2026-72608 describes a stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01. Authenticated staff with the tools => label_creator permission can execute arbitrary SQL via the image_name field of a patr [truncated]

HIGH Koha Community CVE published 2026-08-11

CVE-2026-72607

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:43.867Z and has not been modified since then. This stored SQL injection vulnerability in Koha allows authenticated staff with specific permissions to read arbitrary database contents. The vulnerability arises from the agefield value of an automatic item modification rule being stored verbat [truncated]

HIGH Koha Community CVE published 2026-08-05

CVE-2026-71288

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T13:24:53.583Z and has not been modified since then. CVE-2026-71288 is a SQL injection vulnerability in Koha's guided report builder feature. The vulnerability allows low-privilege staff accounts with create_reports or execute_reports permissions to perform time-based blind SQL injection against t [truncated]

HIGH Koha Community CVE published 2026-08-04

CVE-2026-70373

The CVE-2026-70373 vulnerability affects Koha, an open-source integrated library system. The vulnerability class is SQL injection, which allows an authenticated staff user with reports module permission to inject arbitrary SQL and potentially read any table accessible by the Koha database user. The likely operational impact is unauthorized access to sensitive information such as borrower data, API keys, a [truncated]

HIGH Koha Community CVE published 2026-08-04

CVE-2026-70372

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T13:18:58.040Z and has not been modified since then. Koha's reports/bor_issues_top.pl is vulnerable to SQL injection. An authenticated staff user with reports module permissions can inject arbitrary SQL by manipulating request parameters, allowing access to sensitive data such as borrowers, api_ke [truncated]

HIGH Koha Community CVE published 2026-08-04

CVE-2026-70371

Koha's reports/issues_avg_stats.pl is vulnerable to SQL injection due to user-controlled request parameters being concatenated directly into the query string without validation or parameterization. This allows an authenticated staff user with reports module permission to inject arbitrary SQL and potentially read sensitive data from tables accessible by the Koha database user. The vulnerability can be miti [truncated]

HIGH Koha Community CVE published 2026-08-04

CVE-2026-70370

Koha's reports/catalogue_stats.pl is vulnerable to SQL injection due to user-controlled input being directly interpolated into SQL queries without whitelist validation. An authenticated staff user with reports module permission can inject arbitrary SQL and read any table accessible by the Koha database user. This vulnerability affects Koha users and administrators, especially those with reports module per [truncated]

HIGH Koha Community CVE published 2026-08-04

CVE-2026-70369

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T13:18:57.680Z and has not been modified since then. The reports/acquisitions_stats.pl script in Koha interpolates user-controlled Filter request parameters directly into WHERE fragments of a SQL query without bound parameters. This allows an authenticated staff user with reports module permission [truncated]

MEDIUM Koha Community CVE published 2026-06-13

CVE-2026-6428

CVE-2026-6428 is a SQL injection vulnerability in Koha Community Koha through various versions. An authenticated staff user with the Reports module flag can use the Filter URL parameter in reports/catalogue_out.pl to read arbitrary data from the Koha application database when the Criteria parameter matches /branchcode/. The vulnerability is due to the vulnerable sink in sub calculate concatenating the unm [truncated]

HIGH Koha Community CVE published 2026-03-11

CVE-2026-31844

CVE-2026-31844 is an authenticated SQL Injection vulnerability in the Koha staff interface, specifically in the /cgi-bin/koha/suggestion/suggestion.pl endpoint. The vulnerability is caused by improper validation of the displayby parameter used by the GetDistinctValues functionality. Successful exploitation may lead to full compromise of the backend database, including disclosure or modification of stored [truncated]