Skip to main content

Vendor archive

phpgurukul CVEs

Beta · best-effort

1,062 CVEs tagged to vendor phpgurukul107 Critical, 104 High, 696 Medium, 155 Low, 0 Unrated.

CVE-2024-51226

Published Mar 23, 2026

A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51225

Published Mar 23, 2026

A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary w…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51224

Published Mar 23, 2026

Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitr…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51223

Published Mar 23, 2026

A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51222

Published Mar 23, 2026

A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-3403

Published Mar 2, 2026

A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulatio…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-3402

Published Mar 2, 2026

A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such man…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-70064

Published Feb 18, 2026

PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70063

Published Feb 18, 2026

The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-70062

Published Feb 18, 2026

PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token valid…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55271

Published Feb 17, 2026

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in the profile update functionality of the Use…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2026-2179

Published Feb 8, 2026

A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argumen…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2026-2134

Published Feb 8, 2026

A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unknown function of the file /hms/admin/manage-doctors.php. Suc…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-2088

Published Feb 7, 2026

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of t…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-1550

Published Jan 28, 2026

A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/admin…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-1424

Published Jan 26, 2026

A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation leads to unrestricted upload. It…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-70899

Published Jan 22, 2026

PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-1160

Published Jan 19, 2026

A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of the component Search. The manip…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-1142

Published Jan 19, 2026

A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site request forgery. Th…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-1141

Published Jan 19, 2026

A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component Add Sub-Admin Page.…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2025-70893

Published Jan 15, 2026

A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The application fails to properly sanit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70892

Published Jan 15, 2026

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-70891

Published Jan 15, 2026

A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user management module. The application does not properly sanit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-70890

Published Jan 15, 2026

A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScript code into the username par…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 1,062 CVEsPage 1 of 43