Filtered by vendor Slims Project Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-65233 2 Slims, Slims Project 2 Slims 9 Bulian, Slims 2026-01-05 6.1 Medium
Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.
CVE-2023-24086 1 Slims Project 1 Slims 2025-03-21 6.1 Medium
SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/loan_by_class.php?reportView.
CVE-2018-12658 1 Slims Project 1 Slims 2024-11-21 6.1 Medium
Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_take/index.php?keywords= URI.