VYPR

Blood Donor Management System

by Phpgurukul

CVEs (9)

  • CVE-2022-38813HigNov 25, 2022
    risk 0.53cvss 8.1epss 0.01

    PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group, and Submit Report.

  • CVE-2026-90841HigSep 15, 2026
    risk 0.47cvss 7.3epss

    A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The manipulation of the argument…

  • CVE-2026-90840HigSep 15, 2026
    risk 0.47cvss 7.3epss

    A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be…

  • CVE-2025-4176HigMay 1, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as critical. This vulnerability affects unknown code of the file /admin/request-received-bydonar.php. The manipulation of the argument searchdata leads to sql injection. The…

  • CVE-2025-50487HigJul 28, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hijacking attack.

  • CVE-2024-12955MedDec 26, 2024
    risk 0.31cvss 4.3epss 0.01

    A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as problematic. This vulnerability affects unknown code of the file /logout.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The…

  • CVE-2022-40470MedNov 21, 2022
    risk 0.31cvss 4.8epss 0.01

    Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.

  • CVE-2026-90842LowSep 15, 2026
    risk 0.24cvss 3.7epss

    A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/currentpassword/dbcurrentpwd/newpassword…

  • CVE-2024-12982LowDec 27, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in PHPGurukul Blood Bank & Donor Management System 2.4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /bbdms/admin/update-contactinfo.php. The manipulation of the argument Address leads to cross site…