Vulnerabilities
1,063 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-51226 | A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allows attacker A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Search parameter. NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2026-3403 +1 in the same advisory: …3402 | A vulnerability was detected in PHPGurukul Student Record Management System 1.0. A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used. NVD description · AI analysis pending | 1.9 | <1% | PoC |
| — | |
| CVE-2025-70064 | PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This allows any self-registered user to takeover the application, view confidential logs, and modify system data. NVD description · AI analysis pending | 8.8 group max | <1% | PoC ×2 |
| — | |
| CVE-2024-55270 | phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter. phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter. NVD description · AI analysis pending | 8.8 | <1% | PoC ×2 |
| — | |
| CVE-2024-55271 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in the profile update functionality of the User Panel, specifically the /profile.php endpoint. NVD description · AI analysis pending | 3.5 | <1% | PoC ×2 |
| — | |
| CVE-2026-2179 +1 in the same advisory: …2134 | A vulnerability was determined in PHPGurukul Hospital Management System 4.0. A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. NVD description · AI analysis pending | 2.0 | <1% | PoC ×2 |
| — | |
| CVE-2026-2088 | A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2026-1550 | A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2026-1424 | A vulnerability was identified in PHPGurukul News Portal 1.0. A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. NVD description · AI analysis pending | 2.0 | <1% | PoC |
| — | |
| CVE-2025-70899 | PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf of authenticated administrators by tricking them into visiting a malicious webpage. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2026-1160 | A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of the component Search. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2026-1141 +1 in the same advisory: …1142 | A vulnerability was identified in PHPGurukul News Portal 1.0. A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component Add Sub-Admin Page. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit is publicly available and might be used. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2025-70892 | Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2025-69992 | phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2026-0803 +1 in the same advisory: …0733 | A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the file /enroll.php. The manipulation of the argument studentregno/Pincode/session/department/level/course/sem results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2026-0730 | A flaw has been found in PHPGurukul Staff Leave Management System 1.0. A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/slms/adminviews.py of the component SVG File Handler. Executing a manipulation of the argument profile_pic can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used. NVD description · AI analysis pending | 1.9 | <1% | PoC |
| — | |
| CVE-2025-63611 | Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php ar Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php are stored and rendered unescaped in the admin viewer (/admin/complaint-details.php?cid= ). When an administrator opens the complaint, injected HTML/JavaScript executes in the admin's browser. NVD description · AI analysis pending | 8.7 | <1% | PoC |
| — | |
| CVE-2026-0547 | A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-student-profile.php of the component Student Registration Page. The manipulation of the argument photo results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2025-15406 | A flaw has been found in PHPGurukul Online Course Registration up to 3.1. A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2025-15390 | A security flaw has been discovered in PHPGurukul Small CRM 4.0. A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2025-65380 +1 in the same advisory: …65379 | PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated directly into a backend SQL query. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2025-65647 | Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter. NVD description · AI analysis pending | 4.3 | <1% | PoC |
| — | |
| CVE-2025-13577 | A flaw has been found in PHPGurukul Hostel Management System 2.1. A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing a manipulation of the argument cdetails can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. NVD description · AI analysis pending | 2.0 | <1% |
| — | ||
| CVE-2025-63955 | A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an a A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS). NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2024-44659 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2024-44658 | PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php. PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — |