Vulnerability index

Browse CVEs

979 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Vehicle Record Management System MEDIUM 6.1
CVE-2024-51226

A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allo…

No fix yet
Fix from $1,600 2026-03-23
Hospital Management System HIGH 8.8
CVE-2025-70064

PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Adm…

No fix yet
Fix from $1,950 2026-02-18
Hospital Management System MEDIUM 6.5
CVE-2025-70062

PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fai…

No fix yet
Fix from $1,600 2026-02-18
Hospital Management System MEDIUM 6.5
CVE-2025-70063

The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The app…

No fix yet
Fix from $1,600 2026-02-18
Student Management System HIGH 8.8
CVE-2024-55270

phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.

No fix yet
Fix from $1,950 2026-02-17
Hospital Management System HIGH 7.2
CVE-2026-2179

A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. Th…

No fix yet
Fix from $1,950 2026-02-08
Hospital Management System HIGH 7.2
CVE-2026-2134

A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unknown function of the file /hms…

No fix yet
Fix from $1,950 2026-02-08
Beauty Parlour Management System CRITICAL 9.8
CVE-2026-2088

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointme…

Mitigation only
Fix from $2,300 2026-02-07
Hospital Management System HIGH 8.8
CVE-2026-1550

A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /h…

No fix yet
Fix from $1,950 2026-01-28
News Portal HIGH 7.2
CVE-2026-1424

A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation lea…

No fix yet
Fix from $1,950 2026-01-26
Online Course Registration MEDIUM 6.5
CVE-2025-70899

PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform un…

No fix yet
Fix from $1,600 2026-01-22
Directory Management System CRITICAL 9.8
CVE-2026-1160

A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of t…

Mitigation only
Fix from $2,300 2026-01-19
News Portal HIGH 8.8
CVE-2026-1141

A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the…

No fix yet
Fix from $1,950 2026-01-19
News Portal MEDIUM 6.5
CVE-2026-1142

A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in …

No fix yet
Fix from $1,600 2026-01-19
Cyber Cafe Management System CRITICAL 9.8
CVE-2025-70892

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly …

Mitigation only
Fix from $2,300 2026-01-15
Cyber Cafe Management System HIGH 8.8
CVE-2025-70893

A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The appli…

No fix yet
Fix from $1,950 2026-01-15
Cyber Cafe Management System MEDIUM 6.1
CVE-2025-70890

A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScr…

No fix yet
Fix from $1,600 2026-01-15
Cyber Cafe Management System MEDIUM 6.1
CVE-2025-70891

A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user management module. The appli…

No fix yet
Fix from $1,600 2026-01-15
News Portal CRITICAL 9.8
CVE-2025-69991

phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.

No fix yet
Fix from $2,300 2026-01-13
News Portal CRITICAL 9.8
CVE-2025-69992

phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server witho…

Mitigation only
Fix from $2,300 2026-01-13
News Portal CRITICAL 9.1
CVE-2025-69990

phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be dele…

No fix yet
Fix from $2,300 2026-01-13
Hostel Management System HIGH 8.7
CVE-2025-63611

Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-compl…

No fix yet
Fix from $1,950 2026-01-08
Billing System MEDIUM 6.5
CVE-2025-65380

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidate…

Mitigation only
Fix from $1,600 2025-12-02
Billing System MEDIUM 6.5
CVE-2025-65379

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically, the username and mobileno pa…

Mitigation only
Fix from $1,600 2025-12-02
Hostel Management System MEDIUM 5.4
CVE-2025-13577

A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Ex…

Mitigation only
Fix from $1,600 2025-11-24
Student Record System HIGH 7.5
CVE-2025-63955

A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to…

No fix yet
Fix from $1,950 2025-11-18
Online Shopping Portal CRITICAL 9.8
CVE-2024-44659

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

Mitigation only
Fix from $2,300 2025-11-17
Online Shopping Portal MEDIUM 6.5
CVE-2024-44664

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-d…

No fix yet
Fix from $1,600 2025-11-17
Online Shopping Portal MEDIUM 5.4
CVE-2024-44661

PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.

No fix yet
Fix from $1,600 2025-11-17
Online Shopping Portal MEDIUM 6.5
CVE-2024-44660

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.

No fix yet
Fix from $1,600 2025-11-17