PT-2026-77337 · Koha · Koha

·

CVE-2026-41921

·

Published

2026-08-18

·

Updated

2026-08-21

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Koha versions prior to 26.05.02 Koha versions prior to 25.11.07 Koha versions prior to 25.05.13
Description A stored cross-site scripting issue exists in the purchase suggestion handler. Authenticated staff users can inject malicious scripts by submitting unsanitized input during the suggestion save operation. Specifically, crafted HTML or script content can be placed in the title, author, isbn, publishercode, place, collectiontitle, itemtype, and note variables. These inputs are stored without sanitization and subsequently executed in the browser of any staff user who views the suggestion list template.
Recommendations Update to version 26.05.02 or later. Update to version 25.11.07 or later. Update to version 25.05.13 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41921

Affected Products

Koha