VYPR
Vendor

Phpgurukul

Products
101
CVEs
1,160
Across products
872
Status
Private

Products

101
View all 101 products →

Recent CVEs

1,160
View all 1,160 CVEs →
  • CVE-2023-23156CriFeb 27, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.

  • CVE-2023-23163CriFeb 10, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.

  • CVE-2023-23162CriFeb 10, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.

  • CVE-2022-24263CriJan 31, 2022
    risk 0.67cvss 9.8epss 0.08

    Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

  • CVE-2022-29009CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.23

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

  • CVE-2022-29007CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.19

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.

  • CVE-2022-29006CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.19

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.

  • CVE-2020-5307CriJan 7, 2020
    risk 0.65cvss 9.8epss 0.16

    PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and…

  • CVE-2025-70892CriJan 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.

  • CVE-2025-69992CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.01

    phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.

  • CVE-2025-69991CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.00

    phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.

  • CVE-2024-44659CriNov 17, 2025
    risk 0.64cvss 9.8epss 0.00

    PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

  • CVE-2025-56074CriSep 22, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request.

  • CVE-2025-57119CriSep 16, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function

  • CVE-2025-57118CriSep 15, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php

  • CVE-2025-40692CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via  'requestid' parameter in the endpoint '/ofrs/details.php'.

  • CVE-2025-40691CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via  'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'.

  • CVE-2025-40690CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'.

  • CVE-2025-40689CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via  'remark', 'status' and 'requestid' parameters in the endpoint '/ofrs/admin/request-details.php'.

  • CVE-2025-40687CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via  'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'.