slims CVE Vulnerabilities & Metrics

Focus on slims vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About slims Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with slims. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total slims CVEs: 21
Earliest CVE date: 21 Mar 2017, 06:59 UTC
Latest CVE date: 01 Dec 2023, 16:15 UTC

Latest CVE reference: CVE-2023-48893

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical slims CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.19

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 13
4.0-6.9 8
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS slims CVEs

These are the five CVEs with the highest CVSS scores for slims, sorted by severity first and recency.

All CVEs for slims

CVE-2023-48893 slims vulnerability CVSS: 0 01 Dec 2023, 16:15 UTC

SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate.

CVE-2023-48813 slims vulnerability CVSS: 0 01 Dec 2023, 16:15 UTC

Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php.

CVE-2023-45996 slims vulnerability CVSS: 0 31 Oct 2023, 06:15 UTC

SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the reborrowLimit parameter in the member_type.php.

CVE-2023-3744 slims vulnerability CVSS: 0 02 Oct 2023, 14:15 UTC

Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.

CVE-2023-40970 slims vulnerability CVSS: 0 01 Sep 2023, 11:15 UTC

Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php.

CVE-2023-40969 slims vulnerability CVSS: 0 01 Sep 2023, 11:15 UTC

Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.php.

CVE-2023-29850 slims vulnerability CVSS: 0 14 Apr 2023, 14:15 UTC

SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.

CVE-2022-45019 slims vulnerability CVSS: 0 05 Dec 2022, 23:15 UTC

SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter.

CVE-2022-43362 slims vulnerability CVSS: 0 01 Nov 2022, 19:15 UTC

Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php.

CVE-2022-43361 slims vulnerability CVSS: 0 01 Nov 2022, 19:15 UTC

Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component pop_chart.php.

CVE-2022-38292 slims vulnerability CVSS: 0 12 Sep 2022, 21:15 UTC

SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950sru.php.

CVE-2022-38291 slims vulnerability CVSS: 0 12 Sep 2022, 21:15 UTC

SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar.

CVE-2021-45794 slims vulnerability CVSS: 5.0 17 Mar 2022, 12:15 UTC

Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained.

CVE-2021-45793 slims vulnerability CVSS: 5.0 17 Mar 2022, 12:15 UTC

Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.

CVE-2021-45792 slims vulnerability CVSS: 3.5 17 Mar 2022, 11:15 UTC

Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php.

CVE-2021-45791 slims vulnerability CVSS: 6.5 17 Mar 2022, 11:15 UTC

Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /admin/modules/membership/index.php through the dir parameter. It can be used by remotely authenticated librarian users.

CVE-2017-12586 slims vulnerability CVSS: 4.0 06 Aug 2017, 03:29 UTC

SLiMS 8 Akasia through 8.3.1 has an arbitrary file reading issue because of directory traversal in the url parameter to admin/help.php. It can be exploited by remote authenticated librarian users.

CVE-2017-12585 slims vulnerability CVSS: 6.5 06 Aug 2017, 03:29 UTC

SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users.

CVE-2017-12584 slims vulnerability CVSS: 6.8 06 Aug 2017, 03:29 UTC

There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows remote attackers to trick a user into changing to an attacker-controlled password, a complete account takeover, via the passwd1 and passwd2 fields in an admin/modules/system/app_user.php changecurrent=true operation.

CVE-2017-7242 slims vulnerability CVSS: 4.3 23 Mar 2017, 19:59 UTC

Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: the keywords parameter to bibliography/checkout_item.php, bibliography/dl_print.php, bibliography/item.php, bibliography/item_barcode_generator.php, bibliography/printed_card.php, circulation/loan_rules.php, master_file/author.php, master_file/coll_type.php, and master_file/doc_language.php and the quickReturnID field to circulation/ajax_action.php.

CVE-2017-7202 slims vulnerability CVSS: 4.3 21 Mar 2017, 06:59 UTC

Multiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana before 2017-03-16. The vulnerabilities exist due to insufficient filtration of user-supplied data (id) passed to the 'slims7_cendana-master/template/default/detail_template.php' and 'slims7_cendana-master/template/default-rtl/detail_template.php' URLs. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.