CVE-2026-50767: XSS
A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the item type check-in message field (checkinmsg).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50767?
The severity of CVE-2026-50767 is classified as medium with a CVSS score of 5.4.
How do I fix CVE-2026-50767?
To fix CVE-2026-50767, update your Koha Library Management System to a version later than 25.11 that addresses this vulnerability.
What systems are affected by CVE-2026-50767?
CVE-2026-50767 affects all versions of Koha Library Management System from 0 up to 25.11.
What type of vulnerability is CVE-2026-50767?
CVE-2026-50767 is a stored cross-site scripting (XSS) vulnerability.
Who can exploit CVE-2026-50767?
An authenticated remote attacker with administrator privileges can exploit CVE-2026-50767.