Koha Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Koha versions through 25.11. This issue allows remote attackers to execute arbitrary code via the News function. The vulnerability requires authentication to exploit.

Impact

Exploitation of this vulnerability allows attackers to execute scripts in the context of the user, potentially leading to unauthorized actions or data exposure.

Reproduction

To reproduce this vulnerability, log into Koha with an account that has permission to add News entries. Navigate to 'Tools' then 'News' and create a new entry. After saving, edit the post with the text editor and insert a script payload into the content. Save the changes and the script will execute when the main page is loaded.

Added: Mar 5, 2026, 4:31 PM
Updated: Mar 5, 2026, 4:31 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
6.8
remediation
0.0
relevance
3.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.