CVE-2026-50766
CVE-2026-50766
Vexday Risk Score
0Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS —KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
26 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System through 25.11 allows an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field (items.itemnotes).
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →