PT-2026-46041 · Koha+1 · Koha

·

CVE-2026-26378

·

Published

2026-06-03

·

Updated

2026-07-22

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Koha versions prior to 25.11
Description A Cross Site Scripting (XSS) issue exists where a remote attacker can execute arbitrary code through the file upload function within the Invoice features.
Recommendations Update to version 25.11 or later. Restrict access to the file upload function in Invoice features as a temporary mitigation measure.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26378

Affected Products

Koha