CVE-2026-70370: Koha Community Koha

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT DISTINCTROW, GROUP BY, ORDER BY) with no whitelist validation.

Affected products

  • Koha Community Koha: up to and including 24.11.17; from 25.05.00, up to and including 25.05.12; from 25.11.00, up to and including 25.11.06; from 26.05.00, up to and including 26.05.01

Published 2026-08-04. Last modified 2026-08-26.