Exposure of Koha
DMS32
exposure score
843
sites use
0
exploited
1
critical
CVEs
18 resultsCVE-2025-22954CRITICALGetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or EPSS 25.6%CVE-2023-5025LOWKOHA MARC search.pl cross site scriptingEPSS 0.6%CVE-2026-19780HIGHKoha Eval Code Injection Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-31844HIGHAuthenticated SQL Injection in Koha displayby parameter of suggestion.plEPSS 0.6%CVE-2026-70370HIGHKoha - SQL Injection in reports/catalogue_stats.plEPSS 0.6%CVE-2026-70371HIGHKoha - SQL Injection in reports/issues_avg_stats.plEPSS 0.6%CVE-2026-70373HIGHKoha - SQL Injection in reports/issues_stats.plEPSS 0.6%CVE-2026-70372HIGHKoha - SQL Injection in reports/bor_issues_top.plEPSS 0.6%CVE-2026-70369HIGHKoha - SQL Injection in reports/acquisitions_stats.plEPSS 0.6%CVE-2026-71288HIGHKoha SQL Injection via order_by and {order}_ovalue Parameters in guided_reports.plEPSS 0.5%CVE-2018-25101LOWl2c2technologies Koha opac-MARCdetail.pl cross site scriptingEPSS 0.5%CVE-2026-72607HIGHKoha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by AgeEPSS 0.5%CVE-2025-30076HIGHKoha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.EPSS 0.4%CVE-2026-72608MEDIUMKoha Community Koha - Stored SQL Injection via Patron Card Layout image_nameEPSS 0.4%CVE-2026-6428MEDIUMKoha SQL Injection in reports/catalogue_out.pl via Filter URL ParameterEPSS 0.4%CVE-2026-72609HIGHKoha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.plEPSS 0.4%CVE-2026-72610MEDIUMKoha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip GenerationEPSS 0.3%CVE-2026-41921MEDIUMKoha Stored XSS via Purchase Suggestion HandlerEPSS 0.3%