Koha · Koha · CVE-2026-41921
**Name of the Vulnerable Software and Affected Versions**
Koha versions prior to 26.05.02
Koha versions prior to 25.11.07
Koha versions prior to 25.05.13
**Description**
A stored cross-site scripting issue exists in the purchase suggestion handler. Authenticated staff users can inject malicious scripts by submitting unsanitized input during the suggestion save operation. Specifically, crafted HTML or script content can be placed in the `title`, `author`, `isbn`, `publishercode`, `place`, `collectiontitle`, `itemtype`, and `note` variables. These inputs are stored without sanitization and subsequently executed in the browser of any staff user who views the suggestion list template.
**Recommendations**
Update to version 26.05.02 or later.
Update to version 25.11.07 or later.
Update to version 25.05.13 or later.