VYPR

Vendor CVEs

Slims

All CVEs

40 total · sorted by risk
  • CVE-2025-25403CriApr 29, 2025
    risk 0.64cvss 9.8epss 0.00

    Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php.

  • CVE-2023-3744CriOct 2, 2023
    risk 0.64cvss 9.9epss 0.00

    Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.

  • CVE-2022-38292CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.01

    SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950sru.php.

  • CVE-2023-48893HigDec 1, 2023
    risk 0.57cvss 8.8epss 0.01

    SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate.

  • CVE-2023-48813HigDec 1, 2023
    risk 0.57cvss 8.8epss 0.01

    Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php.

  • CVE-2023-45996HigOct 31, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the reborrowLimit parameter in the member_type.php.

  • CVE-2023-40970HigSep 1, 2023
    risk 0.57cvss 8.8epss 0.01

    Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php.

  • CVE-2021-45791HigMar 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /admin/modules/membership/index.php through the dir parameter. It can be used by remotely authenticated…

  • CVE-2018-12659HigJun 22, 2018
    risk 0.57cvss 8.8epss 0.01

    SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter.

  • CVE-2017-12585HigAug 6, 2017
    risk 0.57cvss 8.8epss 0.02

    SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users.

  • CVE-2017-12584HigAug 6, 2017
    risk 0.57cvss 8.8epss 0.01

    There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows remote attackers to trick a user into changing to an attacker-controlled password, a complete…

  • CVE-2025-61488HigOct 20, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary code via the scrap_image.php component and the imageURL parameter

  • CVE-2023-29850HigApr 14, 2023
    risk 0.49cvss 7.5epss 0.01

    SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.

  • CVE-2022-45019HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.01

    SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter.

  • CVE-2021-45794HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained.

  • CVE-2021-45793HigMar 17, 2022
    risk 0.49cvss 7.5epss 0.05

    Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.

  • CVE-2013-4412HigNov 4, 2019
    risk 0.49cvss 7.5epss 0.03

    slim has NULL pointer dereference when using crypt() method from glibc 2.17

  • CVE-2025-26200HigFeb 24, 2025
    risk 0.47cvss 7.2epss 0.01

    SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.

  • CVE-2022-43362HigNov 1, 2022
    risk 0.47cvss 7.2epss 0.01

    Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php.

  • CVE-2025-22980MedJan 22, 2025
    risk 0.44cvss 6.7epss 0.01

    A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php.

  • CVE-2025-45820MedMay 8, 2025
    risk 0.42cvss 6.5epss 0.00

    Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/bibliography/pop_author_edit.php.

  • CVE-2025-45819MedMay 8, 2025
    risk 0.42cvss 6.5epss 0.00

    Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/author.php.

  • CVE-2025-45818MedMay 8, 2025
    risk 0.42cvss 6.5epss 0.00

    Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/item_status.php.

  • CVE-2017-12586MedAug 6, 2017
    risk 0.42cvss 6.5epss 0.03

    SLiMS 8 Akasia through 8.3.1 has an arbitrary file reading issue because of directory traversal in the url parameter to admin/help.php. It can be exploited by remote authenticated librarian users.

  • CVE-2025-65233MedDec 17, 2025
    risk 0.40cvss 6.1epss 0.00

    Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.

  • CVE-2023-40969MedSep 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.php.

  • CVE-2023-24086MedFeb 13, 2023
    risk 0.40cvss 6.1epss 0.00

    SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/loan_by_class.php?reportView.

  • CVE-2022-38291MedSep 12, 2022
    risk 0.40cvss 6.1epss 0.00

    SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar.

  • CVE-2018-12658MedJun 22, 2018
    risk 0.40cvss 6.1epss 0.01

    Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_take/index.php?keywords= URI.

  • CVE-2018-12657MedJun 22, 2018
    risk 0.40cvss 6.1epss 0.01

    Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI.

  • CVE-2018-12656MedJun 22, 2018
    risk 0.40cvss 6.1epss 0.01

    Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/membership/index.php?keywords= URI.

  • CVE-2018-12655MedJun 22, 2018
    risk 0.40cvss 6.1epss 0.01

    Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242.

  • CVE-2018-12654MedJun 22, 2018
    risk 0.40cvss 6.1epss 0.01

    Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibliography/index.php?keywords= URI.

  • CVE-2017-7242MedMar 23, 2017
    risk 0.40cvss 6.1epss 0.01

    Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: the keywords parameter to bibliography/checkout_item.php, bibliography/dl_print.php, bibliography/item.php, bibliography/item_barcode_generator.php,…

  • CVE-2017-7202MedMar 21, 2017
    risk 0.40cvss 6.1epss 0.01

    Multiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana before 2017-03-16. The vulnerabilities exist due to insufficient filtration of user-supplied data (id) passed to the 'slims7_cendana-master/template/default/detail_template.php' and…

  • CVE-2024-25288MedFeb 21, 2024
    risk 0.32cvss 4.9epss 0.01

    SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.

  • CVE-2022-43361MedNov 1, 2022
    risk 0.31cvss 4.8epss 0.00

    Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component pop_chart.php.

  • CVE-2021-45792MedMar 17, 2022
    risk 0.31cvss 4.8epss 0.00

    Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php.

  • CVE-2010-2945Aug 30, 2010
    risk 0.00cvss epss 0.00

    The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.

  • CVE-2009-1756May 22, 2009
    risk 0.00cvss epss 0.00

    SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments.