VYPR

Vendor CVEs

Phpgurukul

All CVEs

1,160 total · sorted by risk
  • CVE-2023-34647MedJun 28, 2023
    risk 0.40cvss 6.1epss 0.00

    PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2023-34652MedJun 28, 2023
    risk 0.40cvss 6.1epss 0.00

    PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.

  • CVE-2023-34651MedJun 28, 2023
    risk 0.40cvss 6.1epss 0.00

    PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2023-34650MedJun 28, 2023
    risk 0.40cvss 6.1epss 0.00

    PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2023-33591MedJun 21, 2023
    risk 0.40cvss 6.1epss 0.00

    User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.

  • CVE-2023-34666MedJun 15, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the admin username parameter.

  • CVE-2022-46128MedJan 26, 2023
    risk 0.40cvss 6.1epss 0.00

    phpgurukul Doctor Appointment Management System V 1.0.0 is vulnerable to Cross Site Scripting (XSS) via searchdata=.

  • CVE-2022-45730MedJan 26, 2023
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search function.

  • CVE-2022-45729MedJan 12, 2023
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee ID parameter.

  • CVE-2022-45728MedJan 12, 2023
    risk 0.40cvss 6.1epss 0.01

    Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.

  • CVE-2022-43369MedDec 6, 2022
    risk 0.40cvss 6.1epss 0.01

    AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component search.php.

  • CVE-2022-31897MedJun 29, 2022
    risk 0.40cvss 6.1epss 0.01

    SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.

  • CVE-2022-29005MedMay 23, 2022
    risk 0.40cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.

  • CVE-2022-29004MedMay 23, 2022
    risk 0.40cvss 6.1epss 0.03

    Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

  • CVE-2021-39412MedNov 5, 2021
    risk 0.40cvss 6.1epss 0.01

    Multiple Cross Site Scripting (XSS) vulnerabilities exists in PHPGurukul Shopping v3.1 via the (1) callback parameter in (a) server_side/scripts/id_jsonp.php, (b) server_side/scripts/jsonp.php, and (c) scripts/objects_jsonp.php, the (2) value parameter in…

  • CVE-2021-39411MedNov 5, 2021
    risk 0.40cvss 6.1epss 0.01

    Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in…

  • CVE-2020-23051MedOct 22, 2021
    risk 0.40cvss 6.1epss 0.01

    Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields.

  • CVE-2021-42223MedOct 13, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.

  • CVE-2021-26303MedJan 29, 2021
    risk 0.40cvss 6.1epss 0.01

    PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.

  • CVE-2020-5193MedJan 14, 2020
    risk 0.40cvss 6.1epss 0.01

    PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.

  • CVE-2020-5308MedJan 9, 2020
    risk 0.40cvss 6.1epss 0.01

    PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php.

  • CVE-2024-46239MedOct 21, 2024
    risk 0.38cvss 5.9epss 0.00

    Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doctor/edit-profile.php and adminremark parameter in /admin/query-details.php.

  • CVE-2024-46238MedOct 21, 2024
    risk 0.38cvss 5.9epss 0.00

    Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php

  • CVE-2024-46241MedSep 23, 2024
    risk 0.38cvss 5.9epss 0.00

    PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.

  • CVE-2024-37798MedJun 17, 2024
    risk 0.38cvss 5.9epss 0.00

    Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.

  • CVE-2024-30979MedApr 17, 2024
    risk 0.38cvss 5.9epss 0.01

    Cross Site Scripting vulnerability in Cyber Cafe Management System 1.0 allows a remote attacker to execute arbitrary code via the compname parameter in edit-computer-details.php.

  • CVE-2021-37808MedOct 27, 2021
    risk 0.38cvss 5.9epss 0.02

    SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind…

  • CVE-2021-37806MedOct 27, 2021
    risk 0.38cvss 5.9epss 0.02

    An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for a number of seconds used…

  • CVE-2020-25270MedOct 8, 2020
    risk 0.38cvss 5.4epss 0.03

    PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.

  • CVE-2025-25462MedFeb 26, 2025
    risk 0.36cvss 5.5epss 0.00

    A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via the propertytype POST request parameter.

  • CVE-2024-48278MedOct 15, 2024
    risk 0.36cvss 5.5epss 0.00

    Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.

  • CVE-2024-0364MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The manipulation of the argument adminremark leads to sql injection. The exploit has been disclosed to the…

  • CVE-2024-0363MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. The…

  • CVE-2024-0362MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/change-password.php. The manipulation of the argument cpass leads to sql injection. The exploit has been…

  • CVE-2024-0361MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in PHPGurukul Hospital Management System 1.0. Affected is an unknown function of the file admin/contact.php. The manipulation of the argument mobnum leads to sql injection. The exploit has been disclosed to the public and may…

  • CVE-2024-0360MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/edit-doctor-specialization.php. The manipulation of the argument doctorspecilization leads to sql injection. The…

  • CVE-2024-0355MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System up to 1.1. Affected is an unknown function of the file add-category.php. The manipulation of the argument category leads to sql injection. The exploit has been disclosed…

  • CVE-2023-7054MedDec 22, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /user/add-notes.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit…

  • CVE-2026-36388MedMay 7, 2026
    risk 0.35cvss 5.4epss 0.00

    A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored…

  • CVE-2026-39112MedApr 20, 2026
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed…

  • CVE-2024-44661MedNov 17, 2025
    risk 0.35cvss 5.4epss 0.00

    PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.

  • CVE-2025-50363MedNov 3, 2025
    risk 0.35cvss 5.4epss 0.00

    Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.

  • CVE-2025-28129MedOct 6, 2025
    risk 0.35cvss 5.4epss 0.00

    Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.

  • CVE-2025-56075MedSep 22, 2025
    risk 0.35cvss 5.4epss 0.00

    A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request.

  • CVE-2025-57145MedSep 16, 2025
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious…

  • CVE-2025-40696MedSep 11, 2025
    risk 0.35cvss 5.4epss 0.00

    Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fullname', 'location' and 'message' parameters via POST at the endpoint '/ofrs/reporting.php'. This…

  • CVE-2025-40695MedSep 11, 2025
    risk 0.35cvss 5.4epss 0.00

    Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'remark', 'status' and 'takeaction' parameters via POST at the endpoint…

  • CVE-2025-40694MedSep 11, 2025
    risk 0.35cvss 5.4epss 0.00

    Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fromdate' and 'todate' parameters via POST at the endpoint '/ofrs/admin/bwdates-report-result.php'.…

  • CVE-2025-40693MedSep 11, 2025
    risk 0.35cvss 5.4epss 0.00

    Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname' parameters…

  • CVE-2025-57576MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.

Page 18 of 24