Koha records
24 published records for vendor koha.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 8.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2015-4632Proof of concept | Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before koha · koha · CWE-22 | High7.5 | — | 51.8% | Oct 18, 2018 |
41Plan | CVE-2015-4633Proof of concept | Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1koha · koha · CWE-89 | Critical9.8 | — | 6.1% | Oct 18, 2018 |
40Plan | CVE-2014-1924No exploit | The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.1koha · koha · CWE-89 | Critical9.8 | — | 2.0% | Jan 24, 2020 |
40Plan | CVE-2014-1925No exploit | SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x bekoha · koha · CWE-89 | Critical9.8 | — | 2.0% | Jan 24, 2020 |
38Monitor | CVE-2024-28740No exploit | Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contentkoha · koha · CWE-79 | Critical9.6 | — | 0.7% | Aug 6, 2024 |
35Monitor | CVE-2015-4639No exploit | Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x beforkoha · koha · CWE-352 | High8.8 | — | 0.6% | Jul 21, 2017 |
35Monitor | CVE-2018-1000669No exploit | KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnerakoha · koha · CWE-352 | High8.8 | — | 0.5% | Sep 6, 2018 |
34Monitor | CVE-2024-28739No exploit | An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.koha · koha · CWE-77 | High7.2 | — | 18.9% | Aug 6, 2024 |
34Monitor | CVE-2026-31844Proof of concept | Authenticated SQL Injection in Koha displayby parameter of suggestion.plkoha · koha · CWE-89 | High8.7 | — | 0.6% | Mar 11, 2026 |
33Monitor | CVE-2015-4630Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and koha · koha · CWE-352 | High8.0 | — | 3.0% | Oct 18, 2018 |
32Monitor | CVE-2024-24337No exploit | CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.koha · koha · CWE-1236 | High8.0 | — | 0.8% | Feb 12, 2024 |
31Monitor | CVE-2014-1923No exploit | Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before koha · koha · CWE-22 | High7.5 | — | 3.5% | Jan 24, 2020 |
31Monitor | CVE-2014-1922No exploit | Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x koha · koha · CWE-22 | High7.5 | — | 2.3% | Jan 24, 2020 |
26Monitor | CVE-2026-26379No exploit | Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration.koha · koha · CWE-918 | Medium6.5 | — | 0.4% | Jun 3, 2026 |
24Monitor | CVE-2018-1000670No exploit | KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability koha · koha · CWE-79 | Medium6.1 | — | 0.6% | Sep 6, 2018 |
24Monitor | CVE-2026-50765No exploit | A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 thrkoha · koha · CWE-79 | Medium6.1 | — | 0.3% | Jun 26, 2026 |
23Monitor | CVE-2011-4715Proof of concept | Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earliekoha · liblime koha · CWE-22 | Medium5.0 | — | 8.6% | Dec 8, 2011 |
22Monitor | CVE-2015-4631Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x koha · koha · CWE-79 | Medium5.4 | — | 3.7% | Oct 18, 2018 |
21Monitor | CVE-2023-5025No exploit | KOHA MARC search.pl cross site scriptingkoha · koha · CWE-79 | Medium5.4 | — | 0.6% | Sep 17, 2023 |
21Monitor | CVE-2026-26378No exploit | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Ikoha · koha · CWE-79 | Medium5.4 | — | 0.5% | Jun 3, 2026 |
21Monitor | CVE-2026-26377No exploit | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.koha · koha · CWE-79 | Medium5.4 | — | 0.5% | Mar 5, 2026 |
21Monitor | CVE-2026-50766No exploit | A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions alkoha · koha · CWE-79 | Medium5.4 | — | 0.3% | Jun 26, 2026 |
21Monitor | CVE-2026-50767No exploit | A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 verkoha · koha · CWE-79 | Medium5.4 | — | 0.3% | Jun 26, 2026 |
17Monitor | CVE-2014-9446No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote attackerkoha · koha · CWE-79 | Medium4.3 | — | 1.2% | Jan 2, 2015 |
- CVE-2015-463246Plan
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before
HighCVSS 7.5Proof of conceptEPSS 52%koha · kohaOct 18, 2018
- CVE-2015-463341Plan
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1
CriticalCVSS 9.8Proof of conceptEPSS 6%koha · kohaOct 18, 2018
- CVE-2014-192440Plan
The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.1
CriticalCVSS 9.8No exploitEPSS 2%koha · kohaJan 24, 2020
- CVE-2014-192540Plan
SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x be
CriticalCVSS 9.8No exploitEPSS 2%koha · kohaJan 24, 2020
- CVE-2024-2874038Monitor
Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-content
CriticalCVSS 9.6No exploitEPSS 1%koha · kohaAug 6, 2024
- CVE-2015-463935Monitor
Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x befor
HighCVSS 8.8No exploitEPSS 1%koha · kohaJul 21, 2017
- CVE-2018-100066935Monitor
KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnera
HighCVSS 8.8No exploitEPSS 0%koha · kohaSep 6, 2018
- CVE-2024-2873934Monitor
An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.
HighCVSS 7.2No exploitEPSS 19%koha · kohaAug 6, 2024
- CVE-2026-3184434Monitor
Authenticated SQL Injection in Koha displayby parameter of suggestion.pl
HighCVSS 8.7Proof of conceptEPSS 1%koha · kohaMar 11, 2026
- CVE-2015-463033Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and
HighCVSS 8.0Proof of conceptEPSS 3%koha · kohaOct 18, 2018
- CVE-2024-2433732Monitor
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.
HighCVSS 8.0No exploitEPSS 1%koha · kohaFeb 12, 2024
- CVE-2014-192331Monitor
Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before
HighCVSS 7.5No exploitEPSS 3%koha · kohaJan 24, 2020
- CVE-2014-192231Monitor
Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x
HighCVSS 7.5No exploitEPSS 2%koha · kohaJan 24, 2020
- CVE-2026-2637926Monitor
Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration.
MediumCVSS 6.5No exploitEPSS 0%koha · kohaJun 3, 2026
- CVE-2018-100067024Monitor
KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 1%koha · kohaSep 6, 2018
- CVE-2026-5076524Monitor
A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 thr
MediumCVSS 6.1No exploitEPSS 0%koha · kohaJun 26, 2026
- CVE-2011-471523Monitor
Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlie
MediumCVSS 5.0Proof of conceptEPSS 9%koha · liblime kohaDec 8, 2011
- CVE-2015-463122Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x
MediumCVSS 5.4Proof of conceptEPSS 4%koha · kohaOct 18, 2018
- CVE-2023-502521Monitor
KOHA MARC search.pl cross site scripting
MediumCVSS 5.4No exploitEPSS 1%koha · kohaSep 17, 2023
- CVE-2026-2637821Monitor
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in I
MediumCVSS 5.4No exploitEPSS 0%koha · kohaJun 3, 2026
- CVE-2026-2637721Monitor
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.
MediumCVSS 5.4No exploitEPSS 0%koha · kohaMar 5, 2026
- CVE-2026-5076621Monitor
A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions al
MediumCVSS 5.4No exploitEPSS 0%koha · kohaJun 26, 2026
- CVE-2026-5076721Monitor
A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 ver
MediumCVSS 5.4No exploitEPSS 0%koha · kohaJun 26, 2026
- CVE-2014-944617Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote attacker
MediumCVSS 4.3No exploitEPSS 1%koha · kohaJan 2, 2015