Slims is a library management software vendor with a narrowly focused product line centered on open-source systems for institutional and academic libraries, spanning variants including Senayan, Akasia, and Slims 7 Cendana. Its vulnerability exposure recurs through web application input-handling and access-control weaknesses: SQL injection, cross-site scripting, server-side request forgery, cross-site request forgery, and path traversal—a pattern characteristic of web-facing applications where user input flows directly into database queries, page rendering, and file-system operations without robust sanitization. The vendor's footprint is compact but notably positioned within the library-systems landscape, where institutional deployments often persist for extended periods and may face constraints on rapid patching. Defenders running these systems should prioritize input validation and access-control hardening; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Slims over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38292CRITICAL SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950 | Sep 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-45793HIGH Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained. | Mar 17, 2022 | 7.5 | 30 | NO | YES |
CVE-2021-45791HIGH Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /adm | Mar 17, 2022 | 8.8 | 27 | NO | NO |
CVE-2017-12584HIGH There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows | Aug 6, 2017 | 8.8 | 27 | NO | NO |
CVE-2023-3744HIGH Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the conte | Oct 2, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-45996HIGH SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code v | Oct 31, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-48893HIGH SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate. | Dec 1, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-48813HIGH Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php. | Dec 1, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-40970HIGH Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php. | Sep 1, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-29850HIGH SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation an | Apr 14, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Slims.
Media articles that mention a CVE ID that affects a product developed by Slims — matched by CVE ID, not by vendor name.