VYPR

Vendor CVEs

Phpgurukul

All CVEs

1,160 total · sorted by risk
  • CVE-2023-23156CriFeb 27, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.

  • CVE-2023-23163CriFeb 10, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.

  • CVE-2023-23162CriFeb 10, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.

  • CVE-2022-24263CriJan 31, 2022
    risk 0.67cvss 9.8epss 0.08

    Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.

  • CVE-2022-29009CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.23

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

  • CVE-2022-29007CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.19

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.

  • CVE-2022-29006CriMay 11, 2022
    risk 0.65cvss 9.8epss 0.19

    Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.

  • CVE-2020-5307CriJan 7, 2020
    risk 0.65cvss 9.8epss 0.16

    PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and…

  • CVE-2025-70892CriJan 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.

  • CVE-2025-69992CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.01

    phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.

  • CVE-2025-69991CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.00

    phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.

  • CVE-2024-44659CriNov 17, 2025
    risk 0.64cvss 9.8epss 0.00

    PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

  • CVE-2025-56074CriSep 22, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request.

  • CVE-2025-57119CriSep 16, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function

  • CVE-2025-57118CriSep 15, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php

  • CVE-2025-40692CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via  'requestid' parameter in the endpoint '/ofrs/details.php'.

  • CVE-2025-40691CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via  'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'.

  • CVE-2025-40690CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'.

  • CVE-2025-40689CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via  'remark', 'status' and 'requestid' parameters in the endpoint '/ofrs/admin/request-details.php'.

  • CVE-2025-40687CriSep 11, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via  'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'.

  • CVE-2025-56214CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.00

    phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.

  • CVE-2025-56212CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.00

    phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.

  • CVE-2023-41527CriAug 7, 2025
    risk 0.64cvss 9.8epss 0.00

    Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.

  • CVE-2024-51360CriMay 23, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file

  • CVE-2024-51101CriMay 23, 2025
    risk 0.64cvss 9.8epss 0.00

    PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php.

  • CVE-2025-45885CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.00

    PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and use it directly in SQL queries.

  • CVE-2025-45018CriApr 30, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the todate parameter.

  • CVE-2025-45017CriApr 30, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability was discovered in edit-ticket.php of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the tprice POST request parameter.

  • CVE-2025-45949CriApr 28, 2025
    risk 0.64cvss 9.8epss 0.01

    A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable…

  • CVE-2025-45947CriApr 28, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component

  • CVE-2025-25389CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.

  • CVE-2025-25388CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the editid GET request parameter.

  • CVE-2025-25351CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.00

    PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter.

  • CVE-2025-25349CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.00

    PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter.

  • CVE-2024-57687CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.03

    An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "Cookie" GET request parameter.

  • CVE-2024-57686CriJan 10, 2025
    risk 0.64cvss 9.8epss 0.02

    A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "pagetitle" parameter.

  • CVE-2024-54811CriDec 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "login" parameter.

  • CVE-2024-54810CriDec 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the mobileno parameter.

  • CVE-2024-55099CriDec 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.

  • CVE-2024-54842CriDec 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.

  • CVE-2024-53480CriDec 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.

  • CVE-2024-53604CriNov 27, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the mobnumber POST request parameter.

  • CVE-2024-50989CriNov 11, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System v1.0 allows an attacker to execute arbitrary SQL commands via the "searchdata " parameter.

  • CVE-2024-51065CriOct 31, 2024
    risk 0.64cvss 9.8epss 0.01

    Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.

  • CVE-2024-51064CriOct 31, 2024
    risk 0.64cvss 9.8epss 0.01

    Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.

  • CVE-2024-48283CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.

  • CVE-2024-8470CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in it.

  • CVE-2024-8469CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in it.

  • CVE-2024-8468CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in it.

  • CVE-2024-8467CriSep 5, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in it.

Page 1 of 24