LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-31844

CVE-2026-31844 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: March 11, 2026

Koha - SQL Injection

Published: March 11, 2026Updated: March 11, 2026PoC AvailableRemote Exploitable

Overview

Koha contains an authenticated SQL injection caused by improper sanitization of the "displayby" parameter in /cgi-bin/koha/suggestion/suggestion.pl, letting low-privileged staff users execute arbitrary SQL queries and retrieve sensitive data.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 4.0%(Probability of exploitation in next 30 days)

Impact

Low-privileged staff users can execute arbitrary SQL queries, leading to sensitive database information disclosure.

Mitigation

Update to the latest version of Koha.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 11, 2026

🟠 CVE-2026-31844 - High (8.8) An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. A lo... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-31844/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-31844
Severity
High
CVSS Score
8.8
Type
sql_injection
Status
unconfirmed
EPSS
4.0%
Social Posts
1

CWE

  • CWE-89

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

4.0%Probability of exploitation in the next 30 days