phpgurukul

1,081 tracked vulnerabilities.

CVE-2026-1424 MEDIUM
PHPGurukul News Portal 1.0 - Unrestricted File Upload in Profile Pic Handler
Jan 26, 2026
CVSS 4.7
EPSS 0.00
CVE-2026-1160 HIGH
PHPGurukul Directory Management System 1.0 - SQL Injection via Search Parameter
Jan 19, 2026
CVSS 7.3
EPSS 0.00
CVE-2026-1142 MEDIUM
PHPGurukul News Portal 1.0 - Cross-Site Request Forgery
Jan 19, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-1141 MEDIUM
PHPGurukul News Portal 1.0 - Incorrect Privilege Assignment in Add Sub-Admin Page
Jan 19, 2026
CVSS 6.3
EPSS 0.00
CVE-2026-0803 MEDIUM
Online Course Registration System < 3.1 - SQL Injection via enroll.php Parameters
Jan 09, 2026
CVSS 6.3
EPSS 0.00
CVE-2026-0733 MEDIUM
Online Course Registration System < 3.1 - SQL Injection via id/cid Parameter in manage-students.php
Jan 09, 2026
CVSS 6.3
EPSS 0.00
CVE-2026-0730 LOW
PHPGurukul Staff Leave Management System 1.0 - Cross-Site Scripting via Profile Pic Argument
Jan 08, 2026
CVSS 2.4
EPSS 0.00
CVE-2026-0547 MEDIUM
Online Course Registration < 3.1 - Unrestricted File Upload via Student Registration Page
Jan 02, 2026
CVSS 6.3
EPSS 0.00
CVE-2025-70064 HIGH
PHPGurukul HMS 4.0 - Privilege Escalation
Feb 18, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-70063 MEDIUM
PHPGurukul Hospital Management System 4.0 - Authorization Bypass via Medical History ViewID Parameter
Feb 18, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-70062 MEDIUM
PHPGurukul Hospital Management System v4.0 - Cross-Site Request Forgery in Add Doctor Module
Feb 18, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-70899 MEDIUM
PHPgurukul Online Course Registration v3.1 - Cross-Site Request Forgery in Administrative Forms
Jan 22, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-70893 HIGH
PHPGurukul Cyber Cafe Management System 1.0 - Authenticated Time-Based Blind SQL Injection via adminname Parameter
Jan 15, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-70892 CRITICAL
Phpgurukul Cyber Cafe Management System 1.0 - SQL Injection via Username Parameter
Jan 15, 2026
CVSS 9.8
EPSS 0.00
CVE-2025-70891 MEDIUM
Phpgurukul Cyber Cafe Management System 1.0 - Stored XSS via User Management uadd Parameter
Jan 15, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-70890 MEDIUM
Cyber Cafe Management System 1.0 - Authenticated Stored Cross-Site Scripting via Username Parameter
Jan 15, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-69992 CRITICAL
phpgurukul News Portal Project V4.1 - Unauthenticated Arbitrary File Upload via upload.php
Jan 13, 2026
CVSS 9.8
EPSS 0.00
CVE-2025-69991 CRITICAL
phpgurukul News Portal Project V4.1 - SQL Injection in check_availablity.php
Jan 13, 2026
CVSS 9.8
EPSS 0.00
CVE-2025-69990 CRITICAL
phpgurukul News Portal Project V4.1 - Info Disclosure
Jan 13, 2026
CVSS 9.1
EPSS 0.00
CVE-2025-63611 HIGH
phpgurukul Hostel Management System v2.1 - XSS
Jan 08, 2026
CVSS 8.7
EPSS 0.00
CVE-2025-15406 MEDIUM
PHPGurukul Online Course Registration < 3.1 - Missing Authorization
Jan 01, 2026
CVSS 6.3
EPSS 0.00
CVE-2025-15390 MEDIUM
PHPGurukul Small CRM < 4.0 - Missing Authorization in /admin/edit-user.php
Dec 31, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-65380 MEDIUM
PHPGurukul Billing System 1.0 - SQL Injection via Username Parameter
Dec 02, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-65379 MEDIUM
PHPGurukul Billing System 1.0 - SQL Injection via Username or Mobileno Parameter
Dec 02, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-65647 MEDIUM
PHPGURUKUL Online Shopping Portal 2.1 - Insecure Direct Object Reference in Track Order Function
Nov 25, 2025
CVSS 4.3
EPSS 0.00