CVE-2026-70370: Koha Community Koha
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT DISTINCTROW, GROUP BY, ORDER BY) with no whitelist validation.
Affected products
- Koha Community Koha: up to and including 24.11.17; from 25.05.00, up to and including 25.05.12; from 25.11.00, up to and including 25.11.06; from 26.05.00, up to and including 26.05.01
Published 2026-08-04. Last modified 2026-08-26.