VYPR

Vendor CVEs

Phpgurukul

All CVEs

1,160 total · sorted by risk
  • CVE-2023-37685MedAug 8, 2023
    risk 0.31cvss 4.8epss 0.00

    Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal.

  • CVE-2023-37684MedAug 8, 2023
    risk 0.31cvss 4.8epss 0.00

    Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal.

  • CVE-2023-37683MedAug 8, 2023
    risk 0.31cvss 4.8epss 0.00

    Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.

  • CVE-2023-31935MedJul 28, 2023
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the emial parameter of admin-profile.php.

  • CVE-2023-31934MedJul 28, 2023
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the adminname parameter of admin-profile.php.

  • CVE-2023-36940MedJul 10, 2023
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.

  • CVE-2023-36376MedJul 10, 2023
    risk 0.31cvss 4.8epss 0.01

    Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.

  • CVE-2023-1909MedApr 7, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file profile.php of the component User Profile Update Handler. The manipulation of the argument name/mobno leads to sql…

  • CVE-2023-26958MedMar 27, 2023
    risk 0.31cvss 4.8epss 0.00

    Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter.

  • CVE-2022-41445MedNov 22, 2022
    risk 0.31cvss 4.8epss 0.01

    A cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Subject page.

  • CVE-2022-40470MedNov 21, 2022
    risk 0.31cvss 4.8epss 0.01

    Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.

  • CVE-2021-27822MedAug 19, 2021
    risk 0.31cvss 4.8epss 0.01

    A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Category field.

  • CVE-2021-33469MedMay 26, 2021
    risk 0.31cvss 4.8epss 0.01

    COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.

  • CVE-2021-27544MedApr 15, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.

  • CVE-2020-24723MedNov 18, 2020
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in the Registration page of the admin panel in PHPGurukul User Registration & Login and User Management System With admin panel 2.1.

  • CVE-2024-46335MedNov 17, 2025
    risk 0.30cvss 4.6epss 0.00

    PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php.

  • CVE-2024-51106MedMay 19, 2025
    risk 0.30cvss 4.6epss 0.00

    A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle parameter.

  • CVE-2024-51102MedMay 23, 2025
    risk 0.29cvss 4.4epss 0.00

    PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabilities at /studentrecordms/login.php via the username and password parameters.

  • CVE-2024-56990MedJan 21, 2025
    risk 0.29cvss 4.5epss 0.00

    PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin/view-patient.php.

  • CVE-2026-1142MedJan 19, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for…

  • CVE-2025-65647MedNov 25, 2025
    risk 0.28cvss 4.3epss 0.00

    Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.

  • CVE-2025-11390MedOct 7, 2025
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php of the component POST Parameter Handler. Executing a manipulation of the argument searchdata can lead to cross site…

  • CVE-2025-11112MedSep 28, 2025
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in PHPGurukul Employee Record Management System 1.3. This impacts an unknown function of the file /myprofile.php. Such manipulation of the argument First name leads to cross site scripting. The attack can be launched remotely. The…

  • CVE-2025-10794MedSep 22, 2025
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in PHPGurukul Car Rental Project 3.0. Affected by this issue is some unknown functionality of the file /carrental/search.php. Executing manipulation of the argument autofocus can lead to cross site scripting. It is possible to launch the attack remotely.…

  • CVE-2025-56254MedSep 2, 2025
    risk 0.28cvss 4.3epss 0.00

    PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability in leave-details.php. An authenticated user can change the leaveid parameter in the URL to access leave application details of other users.

  • CVE-2025-9656MedAug 29, 2025
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely.…

  • CVE-2025-9017MedAug 15, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the file /admin/add-foreigner-ticket.php. The manipulation of the argument visitorname leads to cross site scripting. The attack can be initiated remotely. The…

  • CVE-2025-7946MedJul 22, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /search-visitor.php of the component HTTP POST Request Handler. The manipulation of the argument searchdata…

  • CVE-2025-7944MedJul 21, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in PHPGurukul Taxi Stand Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /search.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate the attack…

  • CVE-2025-7943MedJul 21, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/search-autoortaxi.php. The manipulation of the argument searchdata leads to cross site scripting. The…

  • CVE-2025-7925MedJul 21, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Banquet Booking System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. The manipulation of the argument user_login/userpassword leads to cross site…

  • CVE-2025-7834MedJul 19, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to…

  • CVE-2025-6285MedJun 19, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in PHPGurukul COVID19 Testing Management System 2021. It has been rated as problematic. This issue affects some unknown processing of the file /search-report-result.php. The manipulation of the argument q leads to cross site scripting. The attack may be…

  • CVE-2025-6284MedJun 19, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in PHPGurukul Car Rental Portal 3.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public…

  • CVE-2025-6126MedJun 16, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /contact.php. The manipulation of the argument Name leads to cross site scripting. The attack can…

  • CVE-2025-5975MedJun 10, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in PHPGurukul Rail Pass Management System 1.0. This affects an unknown part of the file /rpms/download-pass.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate…

  • CVE-2025-4939MedMay 19, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vulnerability affects unknown code of the file /admin/new-ccapplication.php. The manipulation leads to cross site scripting. The attack can be initiated…

  • CVE-2025-4862MedMay 18, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /searchdata.php. The manipulation of the argument searchdata leads to cross site scripting. The…

  • CVE-2024-55231MedDec 18, 2024
    risk 0.28cvss 4.3epss 0.00

    An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter…

  • CVE-2024-55058MedDec 17, 2024
    risk 0.28cvss 4.3epss 0.00

    An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the…

  • CVE-2024-10158MedOct 19, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in PHPGurukul Boat Booking System 1.0. Affected is the function session_start. The manipulation leads to session fixiation. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may…

  • CVE-2024-3089MedMar 30, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/manage-ambulance.php of the component Manage Ambulance Page. The manipulation of the argument del leads to…

  • CVE-2024-3086MedMar 30, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file ambulance-tracking.php of the component Ambulance Tracking Page. The manipulation of the argument…

  • CVE-2024-3084MedMar 30, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been rated as problematic. This issue affects some unknown processing of the component Hire an Ambulance Page. The manipulation of the argument Patient Name/Relative Name/Relative Phone…

  • CVE-2024-0286MedJan 7, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file index.php#contact_us of the component Contact Form. The manipulation of the argument Name/Email/Message leads to cross site…

  • CVE-2023-7173MedDec 30, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file registration.php. The manipulation of the argument First Name leads to cross site scripting. It is possible to initiate the…

  • CVE-2023-7055MedDec 22, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /user/profile.php of the component Contact Information Handler. The manipulation of the argument mobilenumber leads to improper…

  • CVE-2023-7052MedDec 22, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been classified as problematic. This affects an unknown part of the file /user/profile.php. The manipulation of the argument name leads to cross-site request forgery. It is possible to initiate the…

  • CVE-2023-7051MedDec 21, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/manage-notes.php of the component Notes Handler. The manipulation of the argument delid leads to…

  • CVE-2023-6766MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Affected is an unknown function of the file /admin/course.php of the component Delete Course Handler. The manipulation of the argument delid leads to…

Page 21 of 24