VYPR

Hospital Management System

by Phpgurukul

CVEs (75)

  • CVE-2026-1550MedJan 28, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper…

  • CVE-2025-6570MedJun 24, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected by this issue is some unknown functionality of the file /doctor/search.php. The manipulation of the argument searchdata leads to sql injection. The attack may…

  • CVE-2020-26628MedJan 10, 2024
    risk 0.40cvss 6.1epss 0.01

    A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile" page and triggered by another user visiting…

  • CVE-2023-34651MedJun 28, 2023
    risk 0.40cvss 6.1epss 0.00

    PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2021-39411MedNov 5, 2021
    risk 0.40cvss 6.1epss 0.01

    Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in…

  • CVE-2020-5193MedJan 14, 2020
    risk 0.40cvss 6.1epss 0.01

    PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.

  • CVE-2024-46239MedOct 21, 2024
    risk 0.38cvss 5.9epss 0.00

    Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doctor/edit-profile.php and adminremark parameter in /admin/query-details.php.

  • CVE-2024-46238MedOct 21, 2024
    risk 0.38cvss 5.9epss 0.00

    Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php

  • CVE-2024-0364MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The manipulation of the argument adminremark leads to sql injection. The exploit has been disclosed to the…

  • CVE-2024-0363MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. The…

  • CVE-2024-0362MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/change-password.php. The manipulation of the argument cpass leads to sql injection. The exploit has been…

  • CVE-2024-0361MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in PHPGurukul Hospital Management System 1.0. Affected is an unknown function of the file admin/contact.php. The manipulation of the argument mobnum leads to sql injection. The exploit has been disclosed to the public and may…

  • CVE-2024-0360MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/edit-doctor-specialization.php. The manipulation of the argument doctorspecilization leads to sql injection. The…

  • CVE-2026-36388MedMay 7, 2026
    risk 0.35cvss 5.4epss 0.00

    A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored…

  • CVE-2024-46237MedOct 9, 2024
    risk 0.35cvss 5.4epss 0.00

    PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.

  • CVE-2021-35388MedOct 28, 2022
    risk 0.35cvss 5.4epss 0.00

    Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.

  • CVE-2022-42206MedOct 21, 2022
    risk 0.35cvss 5.4epss 0.00

    PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.

  • CVE-2022-42205MedOct 21, 2022
    risk 0.35cvss 5.4epss 0.00

    PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.

  • CVE-2020-22167MedJun 22, 2021
    risk 0.35cvss 5.4epss 0.01

    PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.

  • CVE-2020-25271MedOct 8, 2020
    risk 0.35cvss 5.4epss 0.01

    PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.