Stored Cross-Site Scripting Vulnerability in Koha Library Management System
CVE-2026-50766
5.4MEDIUM
What is CVE-2026-50766?
The Koha Library Management System is vulnerable to a stored cross-site scripting (XSS) issue that allows authenticated users with edit_items permissions to execute arbitrary scripts. This vulnerability is present in the OPAC item detail page, particularly through the item public notes field, leading to potential exploitation by injecting malicious web scripts.
