Vulnerabilities (CVE)

Filtered by vendor Phpgurukul Subscribe
Total 473 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-54842 1 Phpgurukul 1 Online Nurse Hiring System 2025-04-03 N/A 9.8 CRITICAL
A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.
CVE-2024-55099 1 Phpgurukul 1 Online Nurse Hiring System 2025-04-03 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.
CVE-2024-54810 1 Phpgurukul 1 Pre-school Enrollment System 2025-04-03 N/A 9.8 CRITICAL
A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the mobileno parameter.
CVE-2024-54811 1 Phpgurukul 1 Park Ticketing Management System 2025-04-03 N/A 9.8 CRITICAL
A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "login" parameter.
CVE-2024-12955 1 Phpgurukul 1 Blood Bank \& Donor Management System 2025-04-03 5.0 MEDIUM 4.3 MEDIUM
A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as problematic. This vulnerability affects unknown code of the file /logout.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-13074 1 Phpgurukul 1 Land Record System 2025-04-03 4.0 MEDIUM 3.5 LOW
A vulnerability classified as problematic has been found in PHPGurukul Land Record System 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2093 1 Phpgurukul 1 Online Library Management System 2025-04-03 2.1 LOW 3.1 LOW
A vulnerability was found in PHPGurukul Online Library Management System 3.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /change-password.php. The manipulation of the argument email/phone number leads to weak password recovery. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CVE-2025-2090 1 Phpgurukul 1 Pre-school Enrollment System 2025-04-03 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php of the component Sub Admin Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2047 1 Phpgurukul 1 Art Gallery Management System 2025-04-03 4.0 MEDIUM 3.5 LOW
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /search.php. The manipulation of the argument search leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-1952 1 Phpgurukul 1 Restaurant Table Booking System 2025-04-03 7.5 HIGH 7.3 HIGH
A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/password-recovery.php. The manipulation of the argument username/mobileno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12977 1 Phpgurukul 1 Complaint Management System 2025-04-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 1.0. This affects an unknown part of the file /admin/state.php. The manipulation of the argument state leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-12982 1 Phpgurukul 1 Blood Bank \& Donor Management System 2025-04-03 3.3 LOW 2.4 LOW
A vulnerability was found in PHPGurukul Blood Bank & Donor Management System 2.4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /bbdms/admin/update-contactinfo.php. The manipulation of the argument Address leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-13001 1 Phpgurukul 1 Small Crm 2025-04-03 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in PHPGurukul Small CRM 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-10157 1 Phpgurukul 1 Boat Booking System 2025-04-03 7.5 HIGH 7.3 HIGH
A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/password-recovery.php of the component Reset Your Password Page. The manipulation of the argument username/mobileno leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-37798 1 Phpgurukul 1 Beauty Parlour Management System 2025-04-03 N/A 5.9 MEDIUM
Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.
CVE-2024-34987 1 Phpgurukul 1 Online Fire Reporting System 2025-04-03 N/A 9.1 CRITICAL
A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the login process.
CVE-2024-35511 1 Phpgurukul 1 Men Salon Management System 2025-04-03 N/A 4.7 MEDIUM
phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/index.php.
CVE-2025-26156 1 Phpgurukul 1 Online Shopping Portal Project 2025-04-02 N/A 8.8 HIGH
A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter.
CVE-2025-1966 1 Phpgurukul 1 Pre-school Enrollment System 2025-04-02 7.5 HIGH 7.3 HIGH
A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2627 1 Phpgurukul 1 Art Gallery Management System 2025-04-02 6.5 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The manipulation of the argument pagetitle leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.