Stored Cross-Site Scripting in Koha Affected by Unsanitized Input
CVE-2026-41921

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-41921?

Koha Integrated Library System versions prior to 26.05.02, 25.11.07, and 25.05.13 exhibit a stored cross-site scripting vulnerability in the purchase suggestion handler. This issue enables authenticated staff users to inject malicious scripts through unsanitized input during the suggestion save process. Attackers can enter harmful HTML or script content in various fields, including title, author, ISBN, publisher code, place, collection title, item type, and note. These inputs are stored without proper sanitization, leading to potential script execution in the browsers of any staff user reviewing the suggestions.

Affected Version(s)

Koha 26.05.0

Koha 26.05.0 < 26.05.02

Koha 25.11.0 < 25.11.07

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams from Pellera Technologies
VulnCheck
.