CuppaCMS prior to 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.
cuppacms cuppacms