CVE-2025-61488

High severity, CVSS 7.6. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary code via the scrap_image.php component and the imageURL parameter

Published 2025-10-20. Last modified 2026-06-17.