Cross Site Scripting Vulnerability in Koha by Koha Community
CVE-2026-26378

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 June 2026

What is CVE-2026-26378?

A Cross Site Scripting vulnerability exists in Koha versions 25.11 and prior, enabling remote attackers to execute arbitrary code through manipulation of the file upload functionality within the Invoice features. This flaw can potentially be exploited to compromise the security of the impacted system, making it crucial for users to apply available patches and follow best practices for secure coding.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.