Home
Description
Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice features
References
g03m0n.github.io/posts/cve-2026-26378/
github.com/Koha-Community/Koha
g03m0n.github.io/posts/cve-2026-26378/