CVE-2025-69992
CRITICALPhpgurukul News Portal - Out-of-Bounds Read
Title source: ruleDescription
phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.
Scores
CVSS v3
9.8
EPSS
0.0009
EPSS Percentile
25.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-125
Status
published
Affected Products (1)
phpgurukul/news_portal
Timeline
Published
Jan 13, 2026
Tracked Since
Feb 18, 2026