In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
- https://www.exploit-db.com/exploits/45062/
No PoCs found on GitHub currently.