THREAT OPS › Threat News › [NVD] CVE-2026-41921 (MEDIUM 5.4) — Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input through the suggestion save operation. Attackers
[NVD] CVE-2026-41921 (MEDIUM 5.4) — Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input through the suggestion save operation. Attackers
CVE-2026-41921 CVSS: 5.4 MEDIUM Published: 2026-08-18T21:16:34.487
Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input through the suggestion save operation. Attackers can supply crafted HTML or script content in fields
Indicators of compromise
- CVE-2026-41921cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-41921