CVE-2026-50765: XSS
A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the restriction type label (displaytext field).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50765?
CVE-2026-50765 has a medium severity rating of 6.1 according to the CVSS scoring.
How do I fix CVE-2026-50765?
To fix CVE-2026-50765, update your Koha Library Management System to version 26.0 or higher, which addresses the stored XSS vulnerability.
What type of vulnerability is CVE-2026-50765?
CVE-2026-50765 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-50765?
Authenticated remote attackers with administrator privileges on Koha Library Management System versions 0 through 25.11 are affected by CVE-2026-50765.
What can an attacker do with CVE-2026-50765?
An attacker can inject arbitrary web scripts via the patron restriction type label in the Koha Library Management System administration page.