VYPR
Vendor

Slims

Products
9
CVEs
40
Across products
76
Status
Private

Products

9

Recent CVEs

40
View all 40 CVEs →
  • CVE-2025-25403CriApr 29, 2025
    risk 0.64cvss 9.8epss 0.00

    Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php.

  • CVE-2023-3744CriOct 2, 2023
    risk 0.64cvss 9.9epss 0.00

    Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.

  • CVE-2022-38292CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.01

    SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950sru.php.

  • CVE-2023-48893HigDec 1, 2023
    risk 0.57cvss 8.8epss 0.01

    SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate.

  • CVE-2023-48813HigDec 1, 2023
    risk 0.57cvss 8.8epss 0.01

    Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php.

  • CVE-2023-45996HigOct 31, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the reborrowLimit parameter in the member_type.php.

  • CVE-2023-40970HigSep 1, 2023
    risk 0.57cvss 8.8epss 0.01

    Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php.

  • CVE-2021-45791HigMar 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /admin/modules/membership/index.php through the dir parameter. It can be used by remotely authenticated…

  • CVE-2018-12659HigJun 22, 2018
    risk 0.57cvss 8.8epss 0.01

    SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter.

  • CVE-2017-12585HigAug 6, 2017
    risk 0.57cvss 8.8epss 0.02

    SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users.

  • CVE-2017-12584HigAug 6, 2017
    risk 0.57cvss 8.8epss 0.01

    There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows remote attackers to trick a user into changing to an attacker-controlled password, a complete…

  • CVE-2025-61488HigOct 20, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary code via the scrap_image.php component and the imageURL parameter

  • CVE-2023-29850HigApr 14, 2023
    risk 0.49cvss 7.5epss 0.01

    SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.

  • CVE-2022-45019HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.01

    SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter.

  • CVE-2021-45794HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained.

  • CVE-2021-45793HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.05

    Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.

  • CVE-2013-4412HigNov 4, 2019
    risk 0.49cvss 7.5epss 0.03

    slim has NULL pointer dereference when using crypt() method from glibc 2.17

  • CVE-2025-26200HigFeb 24, 2025
    risk 0.47cvss 7.2epss 0.01

    SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.

  • CVE-2022-43362HigNov 1, 2022
    risk 0.47cvss 7.2epss 0.01

    Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php.

  • CVE-2025-22980MedJan 22, 2025
    risk 0.44cvss 6.7epss 0.01

    A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php.