Koha is an open-source library-management system deployed across institutional and public libraries worldwide, presenting a focused but prominent attack surface centered on a single core product. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency to acquire public exploit code, reflecting the product's role in handling sensitive patron and collection data over the web. The exposure recurs persistently through application-layer weakness classes including cross-site scripting, SQL injection, path traversal, cross-site request forgery, and CSV-formula injection, which are characteristic of web-facing database-driven applications with complex input handling and administrative interfaces. Defenders should treat Koha deployments as high-priority for patch management, particularly where instances are internet-reachable or integrated with authentication systems; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Koha over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-4632HIGH Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read ar | Oct 18, 2018 | 7.5 | 65 | NO | YES |
CVE-2025-22954CRITICAL GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter. | Mar 12, 2025 | 10.0 | 45 | NO | NO |
CVE-2015-4633CRITICAL Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute a | Oct 18, 2018 | 9.8 | 43 | NO | YES |
CVE-2015-4630HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attack | Oct 18, 2018 | 8.0 | 32 | NO | YES |
CVE-2011-4715MEDIUM Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows remote attackers to read arbitr | Dec 8, 2011 | 5.0 | 30 | NO | YES |
CVE-2026-50765MEDIUM A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticat | Jun 26, 2026 | 6.1 | 29 | NO | NO |
CVE-2026-31844HIGH An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the di | Mar 11, 2026 | 8.8 | 29 | NO | NO |
CVE-2024-28739HIGH An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter. | Aug 6, 2024 | 7.2 | 29 | NO | NO |
CVE-2026-50767MEDIUM A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote atta | Jun 26, 2026 | 5.4 | 28 | NO | NO |
CVE-2026-50766MEDIUM A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker wit | Jun 26, 2026 | 5.4 | 27 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Koha.
Media articles that mention a CVE ID that affects a product developed by Koha — matched by CVE ID, not by vendor name.