OpenCATS v0.9.6 exists to contain a SQL injection vulnerability via the tag_id variable in the Tag update function.
opencats opencats 0.9.6