VYPR

Vendor CVEs

Phpgurukul

All CVEs

1,160 total · sorted by risk
  • CVE-2025-63955HigNov 18, 2025
    risk 0.49cvss 7.5epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts,…

  • CVE-2025-45805HigSep 3, 2025
    risk 0.49cvss 7.6epss 0.00

    In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an…

  • CVE-2025-57147HigSep 3, 2025
    risk 0.49cvss 7.5epss 0.00

    A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php.

  • CVE-2025-50492HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a session hijacking attack.

  • CVE-2025-50489HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-50494HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-50493HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to execute a session hijacking attack.

  • CVE-2025-50490HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-50349HigJun 23, 2025
    risk 0.49cvss 7.5epss 0.01

    PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php.

  • CVE-2025-50348HigJun 23, 2025
    risk 0.49cvss 7.5epss 0.01

    PHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-class-pic.php.

  • CVE-2025-28072HigApr 16, 2025
    risk 0.49cvss 7.5epss 0.01

    PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.

  • CVE-2024-54790HigDec 19, 2024
    risk 0.49cvss 7.5epss 0.01

    A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remote attackers to execute arbitrary code via the visittime parameter.

  • CVE-2024-51066HigOct 31, 2024
    risk 0.49cvss 7.5epss 0.00

    An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Information (PII) of other customers.

  • CVE-2024-48570HigOct 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php.

  • CVE-2024-48282HigOct 15, 2024
    risk 0.49cvss 7.6epss 0.00

    A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP…

  • CVE-2024-48280HigOct 15, 2024
    risk 0.49cvss 7.6epss 0.00

    A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.

  • CVE-2024-48279HigOct 15, 2024
    risk 0.49cvss 7.6epss 0.01

    A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.

  • CVE-2023-48016HigDec 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Restaurant Table Booking System V1.0 is vulnerable to SQL Injection in rtbs/admin/index.php via the username parameter.

  • CVE-2023-41594HigSep 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via the Username and Password parameters.

  • CVE-2022-24226HigFeb 15, 2022
    risk 0.49cvss 7.5epss 0.02

    Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.

  • CVE-2022-24646HigFeb 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.

  • CVE-2021-44315HigDec 16, 2021
    risk 0.49cvss 7.5epss 0.02

    In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.

  • CVE-2021-44965HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server.

  • CVE-2021-37807HigOct 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.

  • CVE-2020-22176HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.

  • CVE-2020-22175HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22174HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22173HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22172HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22171HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22170HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22169HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22168HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22166HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22165HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.06

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2020-22164HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.

  • CVE-2025-7160HigJul 8, 2025
    risk 0.48cvss 7.3epss 0.02

    A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. This affects an unknown part of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-5579HigJun 4, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected by this issue is some unknown functionality of the file /search-product.php. The manipulation of the argument productname leads to sql injection. The attack may be…

  • CVE-2025-5578HigJun 4, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /sales-report-details.php. The manipulation of the argument fromdate/todate leads to sql…

  • CVE-2025-4793HigMay 16, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Online Course Registration 3.1. It has been classified as critical. Affected is an unknown function of the file /edit-student-profile.php. The manipulation of the argument cgpa leads to sql injection. It is possible to launch the attack…

  • CVE-2025-2473HigMar 18, 2025
    risk 0.48cvss 7.3epss 0.02

    A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php of the component Sign In. The manipulation of the argument username leads to sql injection. The…

  • CVE-2024-13004HigDec 29, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. This affects an unknown part of the file /admin/category.php. The manipulation of the argument state leads to sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2024-12230HigDec 5, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/subcategory.php. The manipulation of the argument category leads to sql injection. The attack…

  • CVE-2024-12229HigDec 5, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in PHPGurukul Complaint Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/complaint-search.php. The manipulation of the argument search leads to sql injection. The attack can be…

  • CVE-2024-12228HigDec 5, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. Affected is an unknown function of the file /admin/user-search.php. The manipulation of the argument search leads to sql injection. It is possible to launch the attack remotely.…

  • CVE-2024-11967HigNov 28, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/reset-password.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack…

  • CVE-2024-11966HigNov 28, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Complaint Management system 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely.…

  • CVE-2024-11965HigNov 28, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in PHPGurukul Complaint Management system 1.0 and classified as critical. This vulnerability affects unknown code of the file /user/reset-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated…

  • CVE-2024-11964HigNov 28, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management system 1.0. This affects an unknown part of the file /user/index.php. The manipulation of the argument emailid leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2024-53603HigNov 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.

Page 4 of 24