CVE-2025-30076: Koha

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Koha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.

Affected products

  • Koha Koha: before 22.11.24 (fixed in 22.11.24); from 23, before 23.11.12 (fixed in 23.11.12); from 24, before 24.05.07 (fixed in 24.05.07); from 24.06, before 24.11.02 (fixed in 24.11.02)

Published 2025-03-16. Last modified 2026-06-17.