VYPR

Vendor CVEs

Phpgurukul

All CVEs

1,160 total · sorted by risk
  • CVE-2025-51671MedJun 26, 2025
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability allows remote attackers to execute arbitrary SQL code via the category and categorycode parameters in a POST request to the manage-categories.php file.

  • CVE-2025-50350MedJun 26, 2025
    risk 0.35cvss 5.4epss 0.00

    PHPGurukul Pre-School Enrollment System Project v1.0 is vulnerable to Directory Traversal in manage-classes.php.

  • CVE-2024-51108MedMay 23, 2025
    risk 0.35cvss 5.4epss 0.00

    Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the…

  • CVE-2024-48702MedMay 23, 2025
    risk 0.35cvss 5.4epss 0.00

    PHPGurukul Old Age Home Management System v1.0 is vulnerable to HTML Injection via the searchdata parameter.

  • CVE-2025-45019MedApr 30, 2025
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability was discovered in /add-foreigners-ticket.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the cprice POST request parameter.

  • CVE-2025-29640MedMar 21, 2025
    risk 0.35cvss 5.4epss 0.00

    Phpgurukul Human Metapneumovirus (HMPV) – Testing Management System v1.0 is vulnerable to SQL Injection in /patient-report.php via the parameter searchdata..

  • CVE-2024-48170MedFeb 10, 2025
    risk 0.35cvss 5.4epss 0.00

    PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.

  • CVE-2024-57175MedFeb 3, 2025
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php.

  • CVE-2024-55232MedDec 18, 2024
    risk 0.35cvss 5.4epss 0.00

    An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete another user's…

  • CVE-2024-55057MedDec 17, 2024
    risk 0.35cvss 5.4epss 0.00

    Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.

  • CVE-2024-55056MedDec 17, 2024
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.

  • CVE-2024-53364MedDec 2, 2024
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.

  • CVE-2024-53365MedNov 26, 2024
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious XSS scripts into the profile name field.

  • CVE-2024-51209MedNov 20, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to inject arbitrary web script or HTML via the search input field parameter to admin search invoice page and client search invoice page.

  • CVE-2024-48807MedOct 30, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter.

  • CVE-2024-46237MedOct 9, 2024
    risk 0.35cvss 5.4epss 0.00

    PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.

  • CVE-2024-40481MedAug 12, 2024
    risk 0.35cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/view-enquiry.php" in PHPGurukul Old Age Home Management System v1.0, which allows remote attackers to execute arbitrary code via the Contact Us page "message" parameter.

  • CVE-2024-30989MedApr 17, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", "comname", "state" and "city" parameter.

  • CVE-2023-47446MedNov 15, 2023
    risk 0.35cvss 5.4epss 0.00

    Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname parameter.

  • CVE-2023-6076MedNov 10, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file booking-details.php of the component Reservation Status Handler. The manipulation of the argument bid…

  • CVE-2023-40851MedOct 16, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the user registration page.

  • CVE-2023-41593MedSep 11, 2023
    risk 0.35cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.

  • CVE-2023-41575MedSep 8, 2023
    risk 0.35cvss 5.4epss 0.00

    Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters.

  • CVE-2023-36375MedJul 10, 2023
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details…

  • CVE-2023-23158MedFeb 27, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the message parameter on the enquiry page.

  • CVE-2023-23157MedFeb 27, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fullname parameter on the enquiry page.

  • CVE-2022-47073MedJan 26, 2023
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter.

  • CVE-2022-47102MedJan 12, 2023
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

  • CVE-2022-43097MedDec 5, 2022
    risk 0.35cvss 5.4epss 0.01

    Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & login pages.

  • CVE-2022-41446MedNov 23, 2022
    risk 0.35cvss 5.4epss 0.01

    An access control issue in /Admin/dashboard.php of Record Management System using CodeIgniter v1.0 allows attackers to access and modify user data.

  • CVE-2021-37781MedOct 28, 2022
    risk 0.35cvss 5.4epss 0.00

    Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.

  • CVE-2021-35388MedOct 28, 2022
    risk 0.35cvss 5.4epss 0.00

    Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.

  • CVE-2022-42206MedOct 21, 2022
    risk 0.35cvss 5.4epss 0.00

    PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.

  • CVE-2022-42205MedOct 21, 2022
    risk 0.35cvss 5.4epss 0.00

    PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.

  • CVE-2020-23466MedAug 19, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in the phpgurukul Online Marriage Registration System 1.0 allows attackers to run arbitrary code via the wzipcode field.

  • CVE-2022-33075MedJul 5, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.

  • CVE-2022-31914MedJun 16, 2022
    risk 0.35cvss 5.4epss 0.00

    Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via zms/admin/public_html/save_animal?an_id=24.

  • CVE-2021-44317MedDec 16, 2021
    risk 0.35cvss 5.4epss 0.01

    In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.

  • CVE-2021-37805MedOct 27, 2021
    risk 0.35cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.

  • CVE-2021-28424MedJul 1, 2021
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.

  • CVE-2020-22167MedJun 22, 2021
    risk 0.35cvss 5.4epss 0.01

    PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.

  • CVE-2020-26052MedFeb 8, 2021
    risk 0.35cvss 5.4epss 0.01

    Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.

  • CVE-2021-26304MedJan 29, 2021
    risk 0.35cvss 5.4epss 0.01

    PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter.

  • CVE-2020-25271MedOct 8, 2020
    risk 0.35cvss 5.4epss 0.01

    PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.

  • CVE-2020-10107MedMar 5, 2020
    risk 0.35cvss 5.4epss 0.01

    PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCost parameter in manage-expense.php.

  • CVE-2025-45021MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management System v2.0. Attackers can exploit this vulnerability via the email parameter in a POST request to execute arbitrary SQL commands.

  • CVE-2025-45011MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata POST request parameter.

  • CVE-2025-45010MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the fromdate and todate POST request parameters.

  • CVE-2025-45009MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    A HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata parameter.

  • CVE-2025-28015MedMar 13, 2025
    risk 0.34cvss 5.3epss 0.00

    A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary HTML code via the fname, lname, and contact parameters.

Page 19 of 24