Vendor CVEs
Phpgurukul
All CVEs
1,160 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-34647 | Med | 0.40 | 6.1 | 0.00 | Jun 28, 2023 | PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2023-34652 | Med | 0.40 | 6.1 | 0.00 | Jun 28, 2023 | PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course. | ||
| CVE-2023-34651 | Med | 0.40 | 6.1 | 0.00 | Jun 28, 2023 | PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2023-34650 | Med | 0.40 | 6.1 | 0.00 | Jun 28, 2023 | PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2023-33591 | Med | 0.40 | 6.1 | 0.00 | Jun 21, 2023 | User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php. | ||
| CVE-2023-34666 | Med | 0.40 | 6.1 | 0.01 | Jun 15, 2023 | Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the admin username parameter. | ||
| CVE-2022-46128 | Med | 0.40 | 6.1 | 0.00 | Jan 26, 2023 | phpgurukul Doctor Appointment Management System V 1.0.0 is vulnerable to Cross Site Scripting (XSS) via searchdata=. | ||
| CVE-2022-45730 | Med | 0.40 | 6.1 | 0.01 | Jan 26, 2023 | A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search function. | ||
| CVE-2022-45729 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2023 | A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee ID parameter. | ||
| CVE-2022-45728 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2023 | Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. | ||
| CVE-2022-43369 | Med | 0.40 | 6.1 | 0.01 | Dec 6, 2022 | AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component search.php. | ||
| CVE-2022-31897 | Med | 0.40 | 6.1 | 0.01 | Jun 29, 2022 | SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=. | ||
| CVE-2022-29005 | Med | 0.40 | 6.1 | 0.02 | May 23, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters. | ||
| CVE-2022-29004 | Med | 0.40 | 6.1 | 0.03 | May 23, 2022 | Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php. | ||
| CVE-2021-39412 | Med | 0.40 | 6.1 | 0.01 | Nov 5, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in PHPGurukul Shopping v3.1 via the (1) callback parameter in (a) server_side/scripts/id_jsonp.php, (b) server_side/scripts/jsonp.php, and (c) scripts/objects_jsonp.php, the (2) value parameter in… | ||
| CVE-2021-39411 | Med | 0.40 | 6.1 | 0.01 | Nov 5, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in… | ||
| CVE-2020-23051 | Med | 0.40 | 6.1 | 0.01 | Oct 22, 2021 | Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields. | ||
| CVE-2021-42223 | Med | 0.40 | 6.1 | 0.01 | Oct 13, 2021 | Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php. | ||
| CVE-2021-26303 | Med | 0.40 | 6.1 | 0.01 | Jan 29, 2021 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field. | ||
| CVE-2020-5193 | Med | 0.40 | 6.1 | 0.01 | Jan 14, 2020 | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter. | ||
| CVE-2020-5308 | Med | 0.40 | 6.1 | 0.01 | Jan 9, 2020 | PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php. | ||
| CVE-2024-46239 | Med | 0.38 | 5.9 | 0.00 | Oct 21, 2024 | Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doctor/edit-profile.php and adminremark parameter in /admin/query-details.php. | ||
| CVE-2024-46238 | Med | 0.38 | 5.9 | 0.00 | Oct 21, 2024 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php | ||
| CVE-2024-46241 | Med | 0.38 | 5.9 | 0.00 | Sep 23, 2024 | PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php. | ||
| CVE-2024-37798 | Med | 0.38 | 5.9 | 0.00 | Jun 17, 2024 | Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field. | ||
| CVE-2024-30979 | Med | 0.38 | 5.9 | 0.01 | Apr 17, 2024 | Cross Site Scripting vulnerability in Cyber Cafe Management System 1.0 allows a remote attacker to execute arbitrary code via the compname parameter in edit-computer-details.php. | ||
| CVE-2021-37808 | Med | 0.38 | 5.9 | 0.02 | Oct 27, 2021 | SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind… | ||
| CVE-2021-37806 | Med | 0.38 | 5.9 | 0.02 | Oct 27, 2021 | An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for a number of seconds used… | ||
| CVE-2020-25270 | Med | 0.38 | 5.4 | 0.03 | Oct 8, 2020 | PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City. | ||
| CVE-2025-25462 | Med | 0.36 | 5.5 | 0.00 | Feb 26, 2025 | A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via the propertytype POST request parameter. | ||
| CVE-2024-48278 | Med | 0.36 | 5.5 | 0.00 | Oct 15, 2024 | Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php. | ||
| CVE-2024-0364 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2024 | A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The manipulation of the argument adminremark leads to sql injection. The exploit has been disclosed to the… | ||
| CVE-2024-0363 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2024 | A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. The… | ||
| CVE-2024-0362 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2024 | A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/change-password.php. The manipulation of the argument cpass leads to sql injection. The exploit has been… | ||
| CVE-2024-0361 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2024 | A vulnerability classified as critical has been found in PHPGurukul Hospital Management System 1.0. Affected is an unknown function of the file admin/contact.php. The manipulation of the argument mobnum leads to sql injection. The exploit has been disclosed to the public and may… | ||
| CVE-2024-0360 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2024 | A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/edit-doctor-specialization.php. The manipulation of the argument doctorspecilization leads to sql injection. The… | ||
| CVE-2024-0355 | Med | 0.36 | 5.5 | 0.01 | Jan 10, 2024 | A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System up to 1.1. Affected is an unknown function of the file add-category.php. The manipulation of the argument category leads to sql injection. The exploit has been disclosed… | ||
| CVE-2023-7054 | Med | 0.36 | 5.5 | 0.01 | Dec 22, 2023 | A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /user/add-notes.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit… | ||
| CVE-2026-36388 | Med | 0.35 | 5.4 | 0.00 | May 7, 2026 | A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored… | ||
| CVE-2026-39112 | Med | 0.35 | 5.4 | 0.00 | Apr 20, 2026 | Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed… | ||
| CVE-2024-44661 | Med | 0.35 | 5.4 | 0.00 | Nov 17, 2025 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php. | ||
| CVE-2025-50363 | Med | 0.35 | 5.4 | 0.00 | Nov 3, 2025 | Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field. | ||
| CVE-2025-28129 | Med | 0.35 | 5.4 | 0.00 | Oct 6, 2025 | Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking. | ||
| CVE-2025-56075 | Med | 0.35 | 5.4 | 0.00 | Sep 22, 2025 | A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request. | ||
| CVE-2025-57145 | Med | 0.35 | 5.4 | 0.00 | Sep 16, 2025 | A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious… | ||
| CVE-2025-40696 | Med | 0.35 | 5.4 | 0.00 | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fullname', 'location' and 'message' parameters via POST at the endpoint '/ofrs/reporting.php'. This… | ||
| CVE-2025-40695 | Med | 0.35 | 5.4 | 0.00 | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'remark', 'status' and 'takeaction' parameters via POST at the endpoint… | ||
| CVE-2025-40694 | Med | 0.35 | 5.4 | 0.00 | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fromdate' and 'todate' parameters via POST at the endpoint '/ofrs/admin/bwdates-report-result.php'.… | ||
| CVE-2025-40693 | Med | 0.35 | 5.4 | 0.00 | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname' parameters… | ||
| CVE-2025-57576 | Med | 0.35 | 5.4 | 0.00 | Sep 4, 2025 | PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php. |
- risk 0.40cvss 6.1epss 0.00
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.00
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.
- risk 0.40cvss 6.1epss 0.00
PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.00
PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.00
User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the admin username parameter.
- risk 0.40cvss 6.1epss 0.00
phpgurukul Doctor Appointment Management System V 1.0.0 is vulnerable to Cross Site Scripting (XSS) via searchdata=.
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search function.
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee ID parameter.
- risk 0.40cvss 6.1epss 0.01
Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
- risk 0.40cvss 6.1epss 0.01
AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component search.php.
- risk 0.40cvss 6.1epss 0.01
SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.
- risk 0.40cvss 6.1epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.
- risk 0.40cvss 6.1epss 0.03
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.
- risk 0.40cvss 6.1epss 0.01
Multiple Cross Site Scripting (XSS) vulnerabilities exists in PHPGurukul Shopping v3.1 via the (1) callback parameter in (a) server_side/scripts/id_jsonp.php, (b) server_side/scripts/jsonp.php, and (c) scripts/objects_jsonp.php, the (2) value parameter in…
- risk 0.40cvss 6.1epss 0.01
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in…
- risk 0.40cvss 6.1epss 0.01
Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.
- risk 0.40cvss 6.1epss 0.01
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.
- risk 0.40cvss 6.1epss 0.01
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.
- risk 0.40cvss 6.1epss 0.01
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php.
- risk 0.38cvss 5.9epss 0.00
Multiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /doctor/edit-profile.php and adminremark parameter in /admin/query-details.php.
- risk 0.38cvss 5.9epss 0.00
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php
- risk 0.38cvss 5.9epss 0.00
PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.
- risk 0.38cvss 5.9epss 0.00
Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.
- risk 0.38cvss 5.9epss 0.01
Cross Site Scripting vulnerability in Cyber Cafe Management System 1.0 allows a remote attacker to execute arbitrary code via the compname parameter in edit-computer-details.php.
- risk 0.38cvss 5.9epss 0.02
SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind…
- risk 0.38cvss 5.9epss 0.02
An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for a number of seconds used…
- risk 0.38cvss 5.4epss 0.03
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
- risk 0.36cvss 5.5epss 0.00
A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via the propertytype POST request parameter.
- risk 0.36cvss 5.5epss 0.00
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.
- risk 0.36cvss 5.5epss 0.01
A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The manipulation of the argument adminremark leads to sql injection. The exploit has been disclosed to the…
- risk 0.36cvss 5.5epss 0.01
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. The…
- risk 0.36cvss 5.5epss 0.01
A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/change-password.php. The manipulation of the argument cpass leads to sql injection. The exploit has been…
- risk 0.36cvss 5.5epss 0.01
A vulnerability classified as critical has been found in PHPGurukul Hospital Management System 1.0. Affected is an unknown function of the file admin/contact.php. The manipulation of the argument mobnum leads to sql injection. The exploit has been disclosed to the public and may…
- risk 0.36cvss 5.5epss 0.01
A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/edit-doctor-specialization.php. The manipulation of the argument doctorspecilization leads to sql injection. The…
- risk 0.36cvss 5.5epss 0.01
A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System up to 1.1. Affected is an unknown function of the file add-category.php. The manipulation of the argument category leads to sql injection. The exploit has been disclosed…
- risk 0.36cvss 5.5epss 0.01
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /user/add-notes.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit…
- risk 0.35cvss 5.4epss 0.00
A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored…
- risk 0.35cvss 5.4epss 0.00
Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed…
- risk 0.35cvss 5.4epss 0.00
PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.
- risk 0.35cvss 5.4epss 0.00
Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.
- risk 0.35cvss 5.4epss 0.00
Phpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.
- risk 0.35cvss 5.4epss 0.00
A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the fromdate parameter in a POST request.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious…
- risk 0.35cvss 5.4epss 0.00
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fullname', 'location' and 'message' parameters via POST at the endpoint '/ofrs/reporting.php'. This…
- risk 0.35cvss 5.4epss 0.00
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'remark', 'status' and 'takeaction' parameters via POST at the endpoint…
- risk 0.35cvss 5.4epss 0.00
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fromdate' and 'todate' parameters via POST at the endpoint '/ofrs/admin/bwdates-report-result.php'.…
- risk 0.35cvss 5.4epss 0.00
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname' parameters…
- risk 0.35cvss 5.4epss 0.00
PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.
Page 18 of 24