Skip to content
Noroxi

Koha records

24 published records for vendor koha.

All records

24 records
  • Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before

    HighCVSS 7.5Proof of conceptEPSS 52%

    koha · kohaOct 18, 2018

  • Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    koha · kohaOct 18, 2018

  • The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.1

    CriticalCVSS 9.8No exploitEPSS 2%

    koha · kohaJan 24, 2020

  • SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x be

    CriticalCVSS 9.8No exploitEPSS 2%

    koha · kohaJan 24, 2020

  • Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-content

    CriticalCVSS 9.6No exploitEPSS 1%

    koha · kohaAug 6, 2024

  • CVE-2015-4639
    35Monitor

    Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x befor

    HighCVSS 8.8No exploitEPSS 1%

    koha · kohaJul 21, 2017

  • KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnera

    HighCVSS 8.8No exploitEPSS 0%

    koha · kohaSep 6, 2018

  • An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.

    HighCVSS 7.2No exploitEPSS 19%

    koha · kohaAug 6, 2024

  • Authenticated SQL Injection in Koha displayby parameter of suggestion.pl

    HighCVSS 8.7Proof of conceptEPSS 1%

    koha · kohaMar 11, 2026

  • CVE-2015-4630
    33Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and

    HighCVSS 8.0Proof of conceptEPSS 3%

    koha · kohaOct 18, 2018

  • CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.

    HighCVSS 8.0No exploitEPSS 1%

    koha · kohaFeb 12, 2024

  • CVE-2014-1923
    31Monitor

    Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before

    HighCVSS 7.5No exploitEPSS 3%

    koha · kohaJan 24, 2020

  • CVE-2014-1922
    31Monitor

    Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x

    HighCVSS 7.5No exploitEPSS 2%

    koha · kohaJan 24, 2020

  • Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration.

    MediumCVSS 6.5No exploitEPSS 0%

    koha · kohaJun 3, 2026

  • KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.1No exploitEPSS 1%

    koha · kohaSep 6, 2018

  • A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 thr

    MediumCVSS 6.1No exploitEPSS 0%

    koha · kohaJun 26, 2026

  • CVE-2011-4715
    23Monitor

    Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlie

    MediumCVSS 5.0Proof of conceptEPSS 9%

    koha · liblime kohaDec 8, 2011

  • CVE-2015-4631
    22Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x

    MediumCVSS 5.4Proof of conceptEPSS 4%

    koha · kohaOct 18, 2018

  • CVE-2023-5025
    21Monitor

    KOHA MARC search.pl cross site scripting

    MediumCVSS 5.4No exploitEPSS 1%

    koha · kohaSep 17, 2023

  • Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in I

    MediumCVSS 5.4No exploitEPSS 0%

    koha · kohaJun 3, 2026

  • Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.

    MediumCVSS 5.4No exploitEPSS 0%

    koha · kohaMar 5, 2026

  • A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions al

    MediumCVSS 5.4No exploitEPSS 0%

    koha · kohaJun 26, 2026

  • A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 ver

    MediumCVSS 5.4No exploitEPSS 0%

    koha · kohaJun 26, 2026

  • CVE-2014-9446
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote attacker

    MediumCVSS 4.3No exploitEPSS 1%

    koha · kohaJan 2, 2015