Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i].
- https://github.com/FiyoCMS/FiyoCMS/issues/5
No PoCs found on GitHub currently.