CVE-2025-52360

HIGH

Koha Library Management System <24.05 - XSS

Title source: llm
STIX 2.1

Description

A Cross-Site Scripting (XSS) vulnerability exists in the OPAC search feature of Koha Library Management System v24.05. Unsanitized input entered in the search field is reflected in the search history interface, leading to the execution of arbitrary JavaScript in the browser context when the user interacts with the interface.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0049
EPSS Percentile 38.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Published Jul 25, 2025
Tracked Since Feb 18, 2026