CVE-2026-50766: XSS
A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edititems permission to inject arbitrary web scripts via the item public notes field (items.itemnotes).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50766?
CVE-2026-50766 has a medium severity rating of 5.4 on the CVSS scale.
How do I fix CVE-2026-50766?
To fix CVE-2026-50766, update the Koha Library Management System to a version beyond 25.11.
What type of vulnerability is CVE-2026-50766?
CVE-2026-50766 is a stored cross-site scripting (XSS) vulnerability affecting the OPAC item detail page of Koha.
Who is affected by CVE-2026-50766?
Authenticated users with edit_items permission in Koha versions 0 through 25.11 are at risk from CVE-2026-50766.
What can attackers do with CVE-2026-50766?
Attackers can inject arbitrary web scripts through the item public notes field due to CVE-2026-50766.