Known Vulnerabilities for products from Slims

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Slims".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-48893 json 8.8 - HIGH 2023-12-01 2023-12-06
CVE-2023-48813 json 8.8 - HIGH 2023-12-01 2023-12-06
CVE-2023-45996 json SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to ob... 8.8 - HIGH 2023-10-31 2023-11-08
CVE-2023-40970 json Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_r... 8.8 - HIGH 2023-09-01 2023-09-07
CVE-2023-40969 json Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/module... 6.1 - MEDIUM 2023-09-01 2023-09-07
CVE-2023-29850 json SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers ... 7.5 - HIGH 2023-04-14 2023-04-25
CVE-2023-3744 json Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to... 8.8 - HIGH 2023-10-02 2023-10-04
CVE-2022-45019 json SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter. 7.5 - HIGH 2022-12-05 2022-12-06
CVE-2022-43362 json Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter a... 7.2 - HIGH 2022-11-01 2022-11-02
CVE-2022-43361 json Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the compone... 4.8 - MEDIUM 2022-11-01 2022-11-02
CVE-2022-38292 json SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the compo... 9.8 - CRITICAL 2022-09-12 2022-09-15
CVE-2022-38291 json SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the S... 6.1 - MEDIUM 2022-09-12 2022-09-15
CVE-2021-45794 json Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained. 7.5 - HIGH 2022-03-17 2022-03-24
CVE-2021-45793 json Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained. 7.5 - HIGH 2022-03-17 2022-03-24
CVE-2021-45792 json Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php. 4.8 - MEDIUM 2022-03-17 2022-03-23
CVE-2021-45791 json Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_t... 8.8 - HIGH 2022-03-17 2022-03-23
CVE-2017-12586 json SLiMS 8 Akasia through 8.3.1 has an arbitrary file reading issue because of directory traversal in the url parameter to admin... Not Provided 2017-08-06 2025-04-20
CVE-2017-12585 json SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin... Not Provided 2017-08-06 2025-04-20
CVE-2017-12584 json There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be upd... Not Provided 2017-08-06 2025-04-20
CVE-2017-7242 json Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: the ke... Not Provided 2017-03-23 2025-04-20

Known software with vulnerabilities from Slims

Type Vendor Product Version
ApplicationSlimsSenayan Library Management System3.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report