Koha kayıtları
koha üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %8,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
46Planlayın | CVE-2015-4632Kavram kanıtı | Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before koha · koha · CWE-22 | Yüksek7,5 | — | %51,8 | 18 Eki 2018 |
41Planlayın | CVE-2015-4633Kavram kanıtı | Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1koha · koha · CWE-89 | Kritik9,8 | — | %6,1 | 18 Eki 2018 |
40Planlayın | CVE-2014-1924İstismar yok | The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.1koha · koha · CWE-89 | Kritik9,8 | — | %2,0 | 24 Oca 2020 |
40Planlayın | CVE-2014-1925İstismar yok | SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x bekoha · koha · CWE-89 | Kritik9,8 | — | %2,0 | 24 Oca 2020 |
38İzleyin | CVE-2024-28740İstismar yok | Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contentkoha · koha · CWE-79 | Kritik9,6 | — | %0,7 | 6 Ağu 2024 |
35İzleyin | CVE-2015-4639İstismar yok | Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x beforkoha · koha · CWE-352 | Yüksek8,8 | — | %0,6 | 21 Tem 2017 |
35İzleyin | CVE-2018-1000669İstismar yok | KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnerakoha · koha · CWE-352 | Yüksek8,8 | — | %0,5 | 6 Eyl 2018 |
34İzleyin | CVE-2024-28739İstismar yok | An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.koha · koha · CWE-77 | Yüksek7,2 | — | %18,9 | 6 Ağu 2024 |
34İzleyin | CVE-2026-31844Kavram kanıtı | Authenticated SQL Injection in Koha displayby parameter of suggestion.plkoha · koha · CWE-89 | Yüksek8,7 | — | %0,6 | 11 Mar 2026 |
33İzleyin | CVE-2015-4630Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and koha · koha · CWE-352 | Yüksek8,0 | — | %3,0 | 18 Eki 2018 |
32İzleyin | CVE-2024-24337İstismar yok | CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.koha · koha · CWE-1236 | Yüksek8,0 | — | %0,8 | 12 Şub 2024 |
31İzleyin | CVE-2014-1923İstismar yok | Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before koha · koha · CWE-22 | Yüksek7,5 | — | %3,5 | 24 Oca 2020 |
31İzleyin | CVE-2014-1922İstismar yok | Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x koha · koha · CWE-22 | Yüksek7,5 | — | %2,3 | 24 Oca 2020 |
26İzleyin | CVE-2026-26379İstismar yok | Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration.koha · koha · CWE-918 | Orta6,5 | — | %0,4 | 3 Haz 2026 |
24İzleyin | CVE-2018-1000670İstismar yok | KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability koha · koha · CWE-79 | Orta6,1 | — | %0,6 | 6 Eyl 2018 |
24İzleyin | CVE-2026-50765İstismar yok | A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 thrkoha · koha · CWE-79 | Orta6,1 | — | %0,3 | 26 Haz 2026 |
23İzleyin | CVE-2011-4715Kavram kanıtı | Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earliekoha · liblime koha · CWE-22 | Orta5,0 | — | %8,6 | 8 Ara 2011 |
22İzleyin | CVE-2015-4631Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x koha · koha · CWE-79 | Orta5,4 | — | %3,7 | 18 Eki 2018 |
21İzleyin | CVE-2023-5025İstismar yok | KOHA MARC search.pl cross site scriptingkoha · koha · CWE-79 | Orta5,4 | — | %0,6 | 17 Eyl 2023 |
21İzleyin | CVE-2026-26378İstismar yok | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Ikoha · koha · CWE-79 | Orta5,4 | — | %0,5 | 3 Haz 2026 |
21İzleyin | CVE-2026-26377İstismar yok | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.koha · koha · CWE-79 | Orta5,4 | — | %0,5 | 5 Mar 2026 |
21İzleyin | CVE-2026-50766İstismar yok | A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions alkoha · koha · CWE-79 | Orta5,4 | — | %0,3 | 26 Haz 2026 |
21İzleyin | CVE-2026-50767İstismar yok | A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 verkoha · koha · CWE-79 | Orta5,4 | — | %0,3 | 26 Haz 2026 |
17İzleyin | CVE-2014-9446İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote attackerkoha · koha · CWE-79 | Orta4,3 | — | %1,2 | 2 Oca 2015 |
- CVE-2015-463246Planlayın
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before
YüksekCVSS 7,5Kavram kanıtıEPSS %52koha · koha18 Eki 2018
- CVE-2015-463341Planlayın
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1
KritikCVSS 9,8Kavram kanıtıEPSS %6koha · koha18 Eki 2018
- CVE-2014-192440Planlayın
The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.1
KritikCVSS 9,8İstismar yokEPSS %2koha · koha24 Oca 2020
- CVE-2014-192540Planlayın
SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x be
KritikCVSS 9,8İstismar yokEPSS %2koha · koha24 Oca 2020
- CVE-2024-2874038İzleyin
Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-content
KritikCVSS 9,6İstismar yokEPSS %1koha · koha6 Ağu 2024
- CVE-2015-463935İzleyin
Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x befor
YüksekCVSS 8,8İstismar yokEPSS %1koha · koha21 Tem 2017
- CVE-2018-100066935İzleyin
KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnera
YüksekCVSS 8,8İstismar yokEPSS %0koha · koha6 Eyl 2018
- CVE-2024-2873934İzleyin
An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.
YüksekCVSS 7,2İstismar yokEPSS %19koha · koha6 Ağu 2024
- CVE-2026-3184434İzleyin
Authenticated SQL Injection in Koha displayby parameter of suggestion.pl
YüksekCVSS 8,7Kavram kanıtıEPSS %1koha · koha11 Mar 2026
- CVE-2015-463033İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and
YüksekCVSS 8,0Kavram kanıtıEPSS %3koha · koha18 Eki 2018
- CVE-2024-2433732İzleyin
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.
YüksekCVSS 8,0İstismar yokEPSS %1koha · koha12 Şub 2024
- CVE-2014-192331İzleyin
Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before
YüksekCVSS 7,5İstismar yokEPSS %3koha · koha24 Oca 2020
- CVE-2014-192231İzleyin
Absolute path traversal vulnerability in tools/pdfViewer.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x
YüksekCVSS 7,5İstismar yokEPSS %2koha · koha24 Oca 2020
- CVE-2026-2637926İzleyin
Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration.
OrtaCVSS 6,5İstismar yokEPSS %0koha · koha3 Haz 2026
- CVE-2018-100067024İzleyin
KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %1koha · koha6 Eyl 2018
- CVE-2026-5076524İzleyin
A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 thr
OrtaCVSS 6,1İstismar yokEPSS %0koha · koha26 Haz 2026
- CVE-2011-471523İzleyin
Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlie
OrtaCVSS 5,0Kavram kanıtıEPSS %9koha · liblime koha8 Ara 2011
- CVE-2015-463122İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x
OrtaCVSS 5,4Kavram kanıtıEPSS %4koha · koha18 Eki 2018
- CVE-2023-502521İzleyin
KOHA MARC search.pl cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1koha · koha17 Eyl 2023
- CVE-2026-2637821İzleyin
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in I
OrtaCVSS 5,4İstismar yokEPSS %0koha · koha3 Haz 2026
- CVE-2026-2637721İzleyin
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.
OrtaCVSS 5,4İstismar yokEPSS %0koha · koha5 Mar 2026
- CVE-2026-5076621İzleyin
A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions al
OrtaCVSS 5,4İstismar yokEPSS %0koha · koha26 Haz 2026
- CVE-2026-5076721İzleyin
A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 ver
OrtaCVSS 5,4İstismar yokEPSS %0koha · koha26 Haz 2026
- CVE-2014-944617İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote attacker
OrtaCVSS 4,3İstismar yokEPSS %1koha · koha2 Oca 2015