joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.
joyplus-cms project joyplus-cms 1.6.0