Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 allows remote attackers to inject arbitrary web script or HTML via a crafted list name.
Conclusion & alert: CVE-2015-4639 is rated Moderate Risk (48.1/100): CVSS High severity, with low exploitation likelihood (EPSS 0.18%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-30 | 0.13% | 0.18% | +0.05% |
| 2 | 2025-03-29 | 0.18% | 0.13% | -0.05% |
| 3 | 2025-03-17 | — | 0.18% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.0 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| koha | koha | 3.14.00 | cpe:2.3:a:koha:koha:3.14.00:*:*:*:*:*:*:* |
| koha | koha | 3.14.00 | cpe:2.3:a:koha:koha:3.14.00:alpha1:*:*:*:*:*:* |
| koha | koha | 3.14.00 | cpe:2.3:a:koha:koha:3.14.00:alpha2:*:*:*:*:*:* |
| koha | koha | 3.14.00 | cpe:2.3:a:koha:koha:3.14.00:beta:*:*:*:*:*:* |
| koha | koha | 3.14.01 | cpe:2.3:a:koha:koha:3.14.01:*:*:*:*:*:*:* |
| koha | koha | 3.14.02 | cpe:2.3:a:koha:koha:3.14.02:*:*:*:*:*:*:* |
| koha | koha | 3.14.03 | cpe:2.3:a:koha:koha:3.14.03:*:*:*:*:*:*:* |
| koha | koha | 3.14.04 | cpe:2.3:a:koha:koha:3.14.04:*:*:*:*:*:*:* |
| koha | koha | 3.14.05 | cpe:2.3:a:koha:koha:3.14.05:*:*:*:*:*:*:* |
| koha | koha | 3.14.06 | cpe:2.3:a:koha:koha:3.14.06:*:*:*:*:*:*:* |
| koha | koha | 3.14.07 | cpe:2.3:a:koha:koha:3.14.07:*:*:*:*:*:*:* |
| koha | koha | 3.14.08 | cpe:2.3:a:koha:koha:3.14.08:*:*:*:*:*:*:* |
| koha | koha | 3.14.09 | cpe:2.3:a:koha:koha:3.14.09:*:*:*:*:*:*:* |
| koha | koha | 3.14.10 | cpe:2.3:a:koha:koha:3.14.10:*:*:*:*:*:*:* |
| koha | koha | 3.14.11 | cpe:2.3:a:koha:koha:3.14.11:*:*:*:*:*:*:* |
| koha | koha | 3.14.12 | cpe:2.3:a:koha:koha:3.14.12:*:*:*:*:*:*:* |
| koha | koha | 3.14.13 | cpe:2.3:a:koha:koha:3.14.13:*:*:*:*:*:*:* |
| koha | koha | 3.14.14 | cpe:2.3:a:koha:koha:3.14.14:*:*:*:*:*:*:* |
| koha | koha | 3.14.15 | cpe:2.3:a:koha:koha:3.14.15:*:*:*:*:*:*:* |
| koha | koha | 3.16.00 | cpe:2.3:a:koha:koha:3.16.00:*:*:*:*:*:*:* |
| koha | koha | 3.16.00 | cpe:2.3:a:koha:koha:3.16.00:beta:*:*:*:*:*:* |
| koha | koha | 3.16.00 | cpe:2.3:a:koha:koha:3.16.00:pkg:*:*:*:*:*:* |
| koha | koha | 3.16.00 | cpe:2.3:a:koha:koha:3.16.00:rc:*:*:*:*:*:* |
| koha | koha | 3.16.01 | cpe:2.3:a:koha:koha:3.16.01:*:*:*:*:*:*:* |
| koha | koha | 3.16.02 | cpe:2.3:a:koha:koha:3.16.02:*:*:*:*:*:*:* |
| koha | koha | 3.16.03 | cpe:2.3:a:koha:koha:3.16.03:*:*:*:*:*:*:* |
| koha | koha | 3.16.04 | cpe:2.3:a:koha:koha:3.16.04:*:*:*:*:*:*:* |
| koha | koha | 3.16.05 | cpe:2.3:a:koha:koha:3.16.05:*:*:*:*:*:*:* |
| koha | koha | 3.16.06 | cpe:2.3:a:koha:koha:3.16.06:*:*:*:*:*:*:* |
| koha | koha | 3.16.07 | cpe:2.3:a:koha:koha:3.16.07:*:*:*:*:*:*:* |
| koha | koha | 3.16.08 | cpe:2.3:a:koha:koha:3.16.08:*:*:*:*:*:*:* |
| koha | koha | 3.16.09 | cpe:2.3:a:koha:koha:3.16.09:*:*:*:*:*:*:* |
| koha | koha | 3.16.10 | cpe:2.3:a:koha:koha:3.16.10:*:*:*:*:*:*:* |
| koha | koha | 3.16.11 | cpe:2.3:a:koha:koha:3.16.11:*:*:*:*:*:*:* |
| koha | koha | 3.20.00 | cpe:2.3:a:koha:koha:3.20.00:*:*:*:*:*:*:* |
| koha | koha | 3.20.00 | cpe:2.3:a:koha:koha:3.20.00:beta:*:*:*:*:*:* |