CVE-2026-50766

A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System through 25.11 allows an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field (items.itemnotes).
CVSS

No CVSS.

Configurations

No configuration.

History

26 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-26 22:16

Updated : 2026-06-26 22:16


NVD link : CVE-2026-50766

Mitre link : CVE-2026-50766

CVE.ORG link : CVE-2026-50766


JSON object : View

Products Affected

No product.

CWE

No CWE.