Перейти к содержимому
Noroxi

Записи Koha

24 опубликованных записей вендора koha.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
8,3 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

24 записей
  • CVE-2015-4632
    46В плане

    Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before

    ВысокаяCVSS 7,5Proof of conceptEPSS 52 %

    koha · koha18 окт. 2018 г.

  • CVE-2015-4633
    41В плане

    Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1

    КритическаяCVSS 9,8Proof of conceptEPSS 6 %

    koha · koha18 окт. 2018 г.

  • CVE-2014-1924
    40В плане

    The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.1

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    koha · koha24 янв. 2020 г.

  • CVE-2014-1925
    40В плане

    SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x be

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    koha · koha24 янв. 2020 г.

  • CVE-2024-28740
    38Наблюдать

    Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-content

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    koha · koha6 авг. 2024 г.

  • CVE-2015-4639
    35Наблюдать

    Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x befor

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    koha · koha21 июл. 2017 г.

  • CVE-2018-1000669
    35Наблюдать

    KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnera

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    koha · koha6 сент. 2018 г.

  • CVE-2024-28739
    34Наблюдать

    An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 19 %

    koha · koha6 авг. 2024 г.

  • CVE-2026-31844
    34Наблюдать

    Authenticated SQL Injection in Koha displayby parameter of suggestion.pl

    ВысокаяCVSS 8,7Proof of conceptEPSS 1 %

    koha · koha11 мар. 2026 г.

  • CVE-2015-4630
    33Наблюдать

    Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and

    ВысокаяCVSS 8,0Proof of conceptEPSS 3 %

    koha · koha18 окт. 2018 г.

  • CVE-2024-24337
    32Наблюдать

    CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.

    ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %

    koha · koha12 февр. 2024 г.

  • CVE-2014-1923
    31Наблюдать

    Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    koha · koha24 янв. 2020 г.

  • CVE-2014-1922
    31Наблюдать

    Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    koha · koha24 янв. 2020 г.

  • CVE-2026-26379
    26Наблюдать

    Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration.

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    koha · koha3 июн. 2026 г.

  • CVE-2018-1000670
    24Наблюдать

    KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    koha · koha6 сент. 2018 г.

  • CVE-2026-50765
    24Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 thr

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    koha · koha26 июн. 2026 г.

  • CVE-2011-4715
    23Наблюдать

    Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlie

    СредняяCVSS 5,0Proof of conceptEPSS 9 %

    koha · liblime koha8 дек. 2011 г.

  • CVE-2015-4631
    22Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x

    СредняяCVSS 5,4Proof of conceptEPSS 4 %

    koha · koha18 окт. 2018 г.

  • CVE-2023-5025
    21Наблюдать

    KOHA MARC search.pl cross site scripting

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    koha · koha17 сент. 2023 г.

  • CVE-2026-26378
    21Наблюдать

    Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in I

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    koha · koha3 июн. 2026 г.

  • CVE-2026-26377
    21Наблюдать

    Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    koha · koha5 мар. 2026 г.

  • CVE-2026-50766
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions al

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    koha · koha26 июн. 2026 г.

  • CVE-2026-50767
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 ver

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    koha · koha26 июн. 2026 г.

  • CVE-2014-9446
    17Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote attacker

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    koha · koha2 янв. 2015 г.