THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-41921 (MEDIUM 5.4) — Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input through the suggestion save operation. Attackers

[NVD] CVE-2026-41921 (MEDIUM 5.4) — Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input through the suggestion save operation. Attackers

mednvdPublished 2026-08-18

CVE-2026-41921 CVSS: 5.4 MEDIUM Published: 2026-08-18T21:16:34.487

Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input through the suggestion save operation. Attackers can supply crafted HTML or script content in fields

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-41921