Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Koha

First CVE: Dec 8, 2011Active for: 15 yearsTotal CVEs: 26
54.8
VTI Score
TOP TARGET

Koha is an open-source library-management system deployed across institutional and public libraries worldwide, presenting a focused but prominent attack surface centered on a single core product. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency to acquire public exploit code, reflecting the product's role in handling sensitive patron and collection data over the web. The exposure recurs persistently through application-layer weakness classes including cross-site scripting, SQL injection, path traversal, cross-site request forgery, and CSV-formula injection, which are characteristic of web-facing database-driven applications with complex input handling and administrative interfaces. Defenders should treat Koha deployments as high-priority for patch management, particularly where instances are internet-reachable or integrated with authentication systems; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Koha over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 8, 2011
14 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-4632HIGH
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read ar
Oct 18, 20187.565NOYES
CVE-2025-22954CRITICAL
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.
Mar 12, 202510.045NONO
CVE-2015-4633CRITICAL
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute a
Oct 18, 20189.843NOYES
CVE-2015-4630HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attack
Oct 18, 20188.032NOYES
CVE-2011-4715MEDIUM
Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime Koha 4.2 and earlier allows remote attackers to read arbitr
Dec 8, 20115.030NOYES
CVE-2026-50765MEDIUM
A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticat
Jun 26, 20266.129NONO
CVE-2026-31844HIGH
An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the di
Mar 11, 20268.829NONO
CVE-2024-28739HIGH
An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.
Aug 6, 20247.229NONO
CVE-2026-50767MEDIUM
A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote atta
Jun 26, 20265.428NONO
CVE-2026-50766MEDIUM
A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker wit
Jun 26, 20265.427NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
42%
38%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (92.3%)
Unknown2 (7.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (88.5%)
High1 (3.8%)
Unknown2 (7.7%)
User Interaction
None11 (42.3%)
Unknown2 (7.7%)
Required13 (50.0%)
Privileges Required
Low9 (34.6%)
High2 (7.7%)
None13 (50.0%)
Unknown2 (7.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.8% of CVEs· 95th percentile
ExploitDB
5 CVEs
19.2% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Koha.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Koha — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Koha's Products

View all 3 CNAs →

Top CWEs