Phpgurukul
Products
101- 75 CVEs
- 48 CVEs
- 44 CVEs
- 44 CVEs
- 36 CVEs
- 36 CVEs
- 35 CVEs
- 32 CVEs
- 32 CVEs
- 32 CVEs
- 31 CVEs
- 31 CVEs
- 29 CVEs
- 28 CVEs
- 25 CVEs
- 25 CVEs
- 24 CVEs
- 24 CVEs
- 23 CVEs
- 23 CVEs
- 22 CVEs
- 21 CVEs
- 20 CVEs
- 20 CVEs
- 20 CVEs
- 20 CVEs
- 20 CVEs
- 18 CVEs
- 17 CVEs
- 17 CVEs
- View all 101 products →
Recent CVEs
1,160| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23156 | Cri | 0.67 | 9.8 | 0.04 | Feb 27, 2023 | Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page. | ||
| CVE-2023-23163 | Cri | 0.67 | 9.8 | 0.04 | Feb 10, 2023 | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter. | ||
| CVE-2023-23162 | Cri | 0.67 | 9.8 | 0.04 | Feb 10, 2023 | Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php. | ||
| CVE-2022-24263 | Cri | 0.67 | 9.8 | 0.08 | Jan 31, 2022 | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter. | ||
| CVE-2022-29009 | Cri | 0.65 | 9.8 | 0.23 | May 11, 2022 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication. | ||
| CVE-2022-29007 | Cri | 0.65 | 9.8 | 0.19 | May 11, 2022 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication. | ||
| CVE-2022-29006 | Cri | 0.65 | 9.8 | 0.19 | May 11, 2022 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication. | ||
| CVE-2020-5307 | Cri | 0.65 | 9.8 | 0.16 | Jan 7, 2020 | PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and… | ||
| CVE-2025-70892 | Cri | 0.64 | 9.8 | 0.00 | Jan 15, 2026 | Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint. | ||
| CVE-2025-69992 | Cri | 0.64 | 9.8 | 0.01 | Jan 13, 2026 | phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication. | ||
| CVE-2025-69991 | Cri | 0.64 | 9.8 | 0.00 | Jan 13, 2026 | phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php. | ||
| CVE-2024-44659 | Cri | 0.64 | 9.8 | 0.00 | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. | ||
| CVE-2025-56074 | Cri | 0.64 | 9.8 | 0.00 | Sep 22, 2025 | A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request. | ||
| CVE-2025-57119 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2025 | An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function | ||
| CVE-2025-57118 | Cri | 0.64 | 9.8 | 0.01 | Sep 15, 2025 | An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php | ||
| CVE-2025-40692 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'requestid' parameter in the endpoint '/ofrs/details.php'. | ||
| CVE-2025-40691 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'. | ||
| CVE-2025-40690 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'. | ||
| CVE-2025-40689 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'remark', 'status' and 'requestid' parameters in the endpoint '/ofrs/admin/request-details.php'. | ||
| CVE-2025-40687 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'. |
- risk 0.67cvss 9.8epss 0.04
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.
- risk 0.67cvss 9.8epss 0.04
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
- risk 0.67cvss 9.8epss 0.04
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.
- risk 0.67cvss 9.8epss 0.08
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
- risk 0.65cvss 9.8epss 0.23
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.
- risk 0.65cvss 9.8epss 0.19
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.
- risk 0.65cvss 9.8epss 0.19
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
- risk 0.65cvss 9.8epss 0.16
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and…
- risk 0.64cvss 9.8epss 0.00
Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.
- risk 0.64cvss 9.8epss 0.01
phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.
- risk 0.64cvss 9.8epss 0.00
phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.
- risk 0.64cvss 9.8epss 0.00
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.
- risk 0.64cvss 9.8epss 0.00
A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request.
- risk 0.64cvss 9.8epss 0.01
An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function
- risk 0.64cvss 9.8epss 0.01
An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php
- risk 0.64cvss 9.8epss 0.00
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'requestid' parameter in the endpoint '/ofrs/details.php'.
- risk 0.64cvss 9.8epss 0.00
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'.
- risk 0.64cvss 9.8epss 0.00
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'.
- risk 0.64cvss 9.8epss 0.00
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'remark', 'status' and 'requestid' parameters in the endpoint '/ofrs/admin/request-details.php'.
- risk 0.64cvss 9.8epss 0.00
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'.