Записи Koha
24 опубликованных записей вендора koha.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 8,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2015-4632Proof of concept | Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before koha · koha · CWE-22 | Высокая7,5 | — | 51,8 % | 18 окт. 2018 г. |
41В плане | CVE-2015-4633Proof of concept | Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1koha · koha · CWE-89 | Критическая9,8 | — | 6,1 % | 18 окт. 2018 г. |
40В плане | CVE-2014-1924Эксплойта нет | The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.1koha · koha · CWE-89 | Критическая9,8 | — | 2,0 % | 24 янв. 2020 г. |
40В плане | CVE-2014-1925Эксплойта нет | SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x bekoha · koha · CWE-89 | Критическая9,8 | — | 2,0 % | 24 янв. 2020 г. |
38Наблюдать | CVE-2024-28740Эксплойта нет | Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contentkoha · koha · CWE-79 | Критическая9,6 | — | 0,7 % | 6 авг. 2024 г. |
35Наблюдать | CVE-2015-4639Эксплойта нет | Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x beforkoha · koha · CWE-352 | Высокая8,8 | — | 0,6 % | 21 июл. 2017 г. |
35Наблюдать | CVE-2018-1000669Эксплойта нет | KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnerakoha · koha · CWE-352 | Высокая8,8 | — | 0,5 % | 6 сент. 2018 г. |
34Наблюдать | CVE-2024-28739Эксплойта нет | An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.koha · koha · CWE-77 | Высокая7,2 | — | 18,9 % | 6 авг. 2024 г. |
34Наблюдать | CVE-2026-31844Proof of concept | Authenticated SQL Injection in Koha displayby parameter of suggestion.plkoha · koha · CWE-89 | Высокая8,7 | — | 0,6 % | 11 мар. 2026 г. |
33Наблюдать | CVE-2015-4630Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and koha · koha · CWE-352 | Высокая8,0 | — | 3,0 % | 18 окт. 2018 г. |
32Наблюдать | CVE-2024-24337Эксплойта нет | CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.koha · koha · CWE-1236 | Высокая8,0 | — | 0,8 % | 12 февр. 2024 г. |
31Наблюдать | CVE-2014-1923Эксплойта нет | Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before koha · koha · CWE-22 | Высокая7,5 | — | 3,5 % | 24 янв. 2020 г. |
31Наблюдать | CVE-2014-1922Эксплойта нет | Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x koha · koha · CWE-22 | Высокая7,5 | — | 2,3 % | 24 янв. 2020 г. |
26Наблюдать | CVE-2026-26379Эксплойта нет | Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration.koha · koha · CWE-918 | Средняя6,5 | — | 0,4 % | 3 июн. 2026 г. |
24Наблюдать | CVE-2018-1000670Эксплойта нет | KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability koha · koha · CWE-79 | Средняя6,1 | — | 0,6 % | 6 сент. 2018 г. |
24Наблюдать | CVE-2026-50765Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 thrkoha · koha · CWE-79 | Средняя6,1 | — | 0,3 % | 26 июн. 2026 г. |
23Наблюдать | CVE-2011-4715Proof of concept | Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earliekoha · liblime koha · CWE-22 | Средняя5,0 | — | 8,6 % | 8 дек. 2011 г. |
22Наблюдать | CVE-2015-4631Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x koha · koha · CWE-79 | Средняя5,4 | — | 3,7 % | 18 окт. 2018 г. |
21Наблюдать | CVE-2023-5025Эксплойта нет | KOHA MARC search.pl cross site scriptingkoha · koha · CWE-79 | Средняя5,4 | — | 0,6 % | 17 сент. 2023 г. |
21Наблюдать | CVE-2026-26378Эксплойта нет | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Ikoha · koha · CWE-79 | Средняя5,4 | — | 0,5 % | 3 июн. 2026 г. |
21Наблюдать | CVE-2026-26377Эксплойта нет | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.koha · koha · CWE-79 | Средняя5,4 | — | 0,5 % | 5 мар. 2026 г. |
21Наблюдать | CVE-2026-50766Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions alkoha · koha · CWE-79 | Средняя5,4 | — | 0,3 % | 26 июн. 2026 г. |
21Наблюдать | CVE-2026-50767Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 verkoha · koha · CWE-79 | Средняя5,4 | — | 0,3 % | 26 июн. 2026 г. |
17Наблюдать | CVE-2014-9446Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote attackerkoha · koha · CWE-79 | Средняя4,3 | — | 1,2 % | 2 янв. 2015 г. |
- CVE-2015-463246В плане
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before
ВысокаяCVSS 7,5Proof of conceptEPSS 52 %koha · koha18 окт. 2018 г.
- CVE-2015-463341В плане
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1
КритическаяCVSS 9,8Proof of conceptEPSS 6 %koha · koha18 окт. 2018 г.
- CVE-2014-192440В плане
The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.1
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %koha · koha24 янв. 2020 г.
- CVE-2014-192540В плане
SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x be
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %koha · koha24 янв. 2020 г.
- CVE-2024-2874038Наблюдать
Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-content
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %koha · koha6 авг. 2024 г.
- CVE-2015-463935Наблюдать
Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x befor
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %koha · koha21 июл. 2017 г.
- CVE-2018-100066935Наблюдать
KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnera
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %koha · koha6 сент. 2018 г.
- CVE-2024-2873934Наблюдать
An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.
ВысокаяCVSS 7,2Эксплойта нетEPSS 19 %koha · koha6 авг. 2024 г.
- CVE-2026-3184434Наблюдать
Authenticated SQL Injection in Koha displayby parameter of suggestion.pl
ВысокаяCVSS 8,7Proof of conceptEPSS 1 %koha · koha11 мар. 2026 г.
- CVE-2015-463033Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and
ВысокаяCVSS 8,0Proof of conceptEPSS 3 %koha · koha18 окт. 2018 г.
- CVE-2024-2433732Наблюдать
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %koha · koha12 февр. 2024 г.
- CVE-2014-192331Наблюдать
Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %koha · koha24 янв. 2020 г.
- CVE-2014-192231Наблюдать
Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %koha · koha24 янв. 2020 г.
- CVE-2026-2637926Наблюдать
Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %koha · koha3 июн. 2026 г.
- CVE-2018-100067024Наблюдать
KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability
СредняяCVSS 6,1Эксплойта нетEPSS 1 %koha · koha6 сент. 2018 г.
- CVE-2026-5076524Наблюдать
A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 thr
СредняяCVSS 6,1Эксплойта нетEPSS 0 %koha · koha26 июн. 2026 г.
- CVE-2011-471523Наблюдать
Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlie
СредняяCVSS 5,0Proof of conceptEPSS 9 %koha · liblime koha8 дек. 2011 г.
- CVE-2015-463122Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x
СредняяCVSS 5,4Proof of conceptEPSS 4 %koha · koha18 окт. 2018 г.
- CVE-2023-502521Наблюдать
KOHA MARC search.pl cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %koha · koha17 сент. 2023 г.
- CVE-2026-2637821Наблюдать
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in I
СредняяCVSS 5,4Эксплойта нетEPSS 0 %koha · koha3 июн. 2026 г.
- CVE-2026-2637721Наблюдать
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %koha · koha5 мар. 2026 г.
- CVE-2026-5076621Наблюдать
A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions al
СредняяCVSS 5,4Эксплойта нетEPSS 0 %koha · koha26 июн. 2026 г.
- CVE-2026-5076721Наблюдать
A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 ver
СредняяCVSS 5,4Эксплойта нетEPSS 0 %koha · koha26 июн. 2026 г.
- CVE-2014-944617Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote attacker
СредняяCVSS 4,3Эксплойта нетEPSS 1 %koha · koha2 янв. 2015 г.