CVE-2026-41921: Koha Stored XSS via Purchase Suggestion Handler

Published Aug 18, 2026
·
Updated

Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input through the suggestion save operation. Attackers can supply crafted HTML or script content in fields such as title, author, isbn, publishercode, place, collectiontitle, itemtype, and note, which are stored without sanitization and later rendered in the suggestion list template, causing injected scripts to execute in the browser of any staff user who views the suggestions.

Affected Software

1 affected component
Koha Koha<26.05.02, <25.11.07, <25.05.13

Event History

Aug 18, 2026
CVE Published
via MITRE·09:09 PM
Data Sourced
via MITRE·09:09 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Authenticated Koha staff users who can submit purchase suggestions can inject the payload. It executes in the browser of staff users who later view the suggestion list, so exposure is limited to installations where staff use this workflow.

2

What does an attacker need to exploit this issue?

An attacker needs authenticated staff access and must submit crafted HTML or script content through the suggestion save operation. No additional technical complexity is indicated, but a staff user must subsequently view the stored suggestion.

3

Which purchase-suggestion fields should be treated as potentially malicious?

The affected input fields include title, author, isbn, publishercode, place, collectiontitle, itemtype, and note. These values are stored without sanitization and rendered in the suggestion list template.

4

Which versions should be updated?

Versions before 26.05.02, 25.11.07, and 25.05.13 are affected. Upgrade to the applicable listed release or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203