VYPR

Vendor CVEs

Phpgurukul

All CVEs

1,160 total · sorted by risk
  • CVE-2021-26822CriFeb 15, 2021
    risk 0.64cvss 9.8epss 0.05

    Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.

  • CVE-2020-25952CriNov 16, 2020
    risk 0.64cvss 9.8epss 0.04

    SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System With admin panel 2.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

  • CVE-2020-23936CriAug 20, 2020
    risk 0.64cvss 9.8epss 0.01

    PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".

  • CVE-2020-12429CriApr 28, 2020
    risk 0.64cvss 9.8epss 0.02

    Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_availability.php, admin/index.php, change-password.php, check_availability.php,…

  • CVE-2020-10225CriMar 8, 2020
    risk 0.64cvss 9.8epss 0.04

    An unauthenticated file upload vulnerability has been identified in admin/gallery.php in PHPGurukul Job Portal 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command…

  • CVE-2020-10224CriMar 8, 2020
    risk 0.64cvss 9.8epss 0.05

    An unauthenticated file upload vulnerability has been identified in admin_add.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command…

  • CVE-2020-10106CriMar 5, 2020
    risk 0.64cvss 9.8epss 0.01

    PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in index.php or register.php. The SQL injection allows to dump the MySQL database and to bypass the login prompt.

  • CVE-2020-5510CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.02

    PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.

  • CVE-2020-5192HigJan 6, 2020
    risk 0.62cvss 8.8epss 0.17

    PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.

  • CVE-2026-39109CriApr 20, 2026
    risk 0.61cvss 9.4epss 0.00

    SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve…

  • CVE-2020-35151HigDec 21, 2020
    risk 0.61cvss 8.8epss 0.04

    The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.

  • CVE-2025-69990CriJan 13, 2026
    risk 0.59cvss 9.1epss 0.00

    phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted.

  • CVE-2025-57148CriSep 3, 2025
    risk 0.59cvss 9.1epss 0.00

    phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.

  • CVE-2025-45953CriApr 28, 2025
    risk 0.59cvss 9.1epss 0.00

    A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely

  • CVE-2024-51063CriOct 31, 2024
    risk 0.59cvss 9.1epss 0.01

    Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.

  • CVE-2024-34987CriJun 3, 2024
    risk 0.59cvss 9.1epss 0.01

    A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the…

  • CVE-2025-51414HigApr 13, 2026
    risk 0.57cvss 8.8epss 0.00

    In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my-profile.php page.

  • CVE-2025-70064HigFeb 18, 2026
    risk 0.57cvss 8.8epss 0.00

    PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after…

  • CVE-2024-55270HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.00

    phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.

  • CVE-2025-70893HigJan 15, 2026
    risk 0.57cvss 8.8epss 0.00

    A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The application fails to properly sanitize user-supplied input provided via the adminname parameter, allowing authenticated attackers to…

  • CVE-2025-63611HigJan 8, 2026
    risk 0.57cvss 8.7epss 0.00

    Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php are stored and rendered unescaped in the admin viewer (/admin/complaint-details.php?cid=). When an administrator…

  • CVE-2025-57151HigSep 3, 2025
    risk 0.57cvss 8.8epss 0.01

    phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter.

  • CVE-2025-26156HigFeb 14, 2025
    risk 0.57cvss 8.8epss 0.01

    A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter.

  • CVE-2024-32254HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.01

    Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are uploaded from the image.

  • CVE-2022-46499HigMar 7, 2024
    risk 0.57cvss 8.8epss 0.01

    Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.

  • CVE-2023-38890HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the…

  • CVE-2023-37772HigAug 1, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.

  • CVE-2021-35387HigOct 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.

  • CVE-2022-28992HigMay 20, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request.

  • CVE-2022-27992HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.02

    Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter.

  • CVE-2021-43137HigDec 1, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.

  • CVE-2021-26764HigJul 22, 2021
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit-std.php.

  • CVE-2021-26762HigJul 22, 2021
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.

  • CVE-2021-28423HigJul 1, 2021
    risk 0.57cvss 8.8epss 0.03

    Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in…

  • CVE-2020-35745HigJan 7, 2021
    risk 0.57cvss 8.8epss 0.02

    PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.

  • CVE-2020-26766HigDec 26, 2020
    risk 0.57cvss 8.8epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability exists in the loginsystem page in PHPGurukul User Registration & Login and User Management System With Admin Panel 2.1.

  • CVE-2020-28136HigNov 17, 2020
    risk 0.57cvss 8.8epss 0.03

    An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.

  • CVE-2020-5511HigJan 8, 2020
    risk 0.57cvss 8.8epss 0.02

    PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page.

  • CVE-2025-56216HigAug 25, 2025
    risk 0.55cvss 8.5epss 0.00

    phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter.

  • CVE-2026-39110HigApr 20, 2026
    risk 0.53cvss 8.2epss 0.00

    SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the contactno parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries during…

  • CVE-2025-57146HigSep 3, 2025
    risk 0.53cvss 8.1epss 0.00

    phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter.

  • CVE-2024-32256HigApr 16, 2024
    risk 0.53cvss 8.1epss 0.01

    Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image.

  • CVE-2022-46497HigMar 7, 2024
    risk 0.53cvss 8.1epss 0.01

    Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php.

  • CVE-2022-38813HigNov 25, 2022
    risk 0.53cvss 8.1epss 0.01

    PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group, and Submit Report.

  • CVE-2025-51672HigJun 26, 2025
    risk 0.52cvss 8.0epss 0.00

    A time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability exists in the manage-companies.php file and allows remote attackers to execute arbitrary SQL code via the companyname parameter in a POST…

  • CVE-2023-46024HigNov 14, 2023
    risk 0.52cvss 7.5epss 0.01

    SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary SQL commands and obtain sensitive information via the 'searchdata' parameter.

  • CVE-2023-0562HigJan 28, 2023
    risk 0.51cvss 7.3epss 0.44

    A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The…

  • CVE-2020-25487HigSep 22, 2020
    risk 0.51cvss 7.8epss 0.01

    PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.

  • CVE-2020-5509HigJan 14, 2020
    risk 0.50cvss 7.2epss 0.06

    PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image.

  • CVE-2026-39111HigApr 20, 2026
    risk 0.49cvss 7.5epss 0.00

    SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries and retrieve…

Page 3 of 24