Koha Community
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 11
en
Verify to analyze this security profile
As of 09/16/2026, Koha Community recorded 11 security vulnerabilities in the last 90 days across 1 products, including 8 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, Koha had the most security vulnerabilities in the Koha Community ecosystem, with 11 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-41921Koha Stored XSS via Purchase Suggestion Handler | Exploitation statusNot known exploited | FixYes | Affected productKoha | Published08/18/2026 | SeverityMedium |
CVE-2026-72610Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation | Exploitation statusNot known exploited | FixYes | Affected productKoha | Published08/11/2026 | SeverityMedium |
CVE-2026-72609Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl | Exploitation statusNot known exploited | FixYes | Affected productKoha | Published08/11/2026 | SeverityHigh |
CVE-2026-72608Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name | Exploitation statusNot known exploited | FixYes | Affected productKoha | Published08/11/2026 | SeverityMedium |
CVE-2026-72607Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by Age | Exploitation statusNot known exploited | FixYes | Affected productKoha | Published08/11/2026 | SeverityHigh |
CVE-2026-71288Koha SQL Injection via order_by and {order}_ovalue Parameters in guided_reports.pl | Exploitation statusNot known exploited | FixYes | Affected productKoha | Published08/05/2026 | SeverityHigh |
CVE-2026-70373Koha - SQL Injection in reports/issues_stats.pl | Exploitation statusNot known exploited | FixYes | Affected productKoha | Published08/04/2026 | SeverityHigh |
CVE-2026-70372Koha - SQL Injection in reports/bor_issues_top.pl | Exploitation statusNot known exploited | FixYes | Affected productKoha | Published08/04/2026 | SeverityHigh |
CVE-2026-70371Koha - SQL Injection in reports/issues_avg_stats.pl | Exploitation statusNot known exploited | FixYes | Affected productKoha | Published08/04/2026 | SeverityHigh |
CVE-2026-70370Koha - SQL Injection in reports/catalogue_stats.pl | Exploitation statusNot known exploited | FixYes | Affected productKoha | Published08/04/2026 | SeverityHigh |
CVE-2026-70369Koha - SQL Injection in reports/acquisitions_stats.pl | Exploitation statusNot known exploited | FixYes | Affected productKoha | Published08/04/2026 | SeverityHigh |
CVE-2026-6428Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter | Exploitation statusPublic exploit | FixYes | Affected productKoha | Published06/13/2026 | SeverityMedium |
CVE-2026-31844Authenticated SQL Injection in Koha displayby parameter of suggestion.pl | Exploitation statusPublic exploit | FixYes | Affected productKoha | Published03/11/2026 | SeverityHigh |