Phpgurukul
phpgurukul
1,063 CVEs • 87 products
Products (87)
Click to collapseToggle
Products (87)
Click to collapse
CVEs (1,063)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request....Show more |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php. |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Nov 17, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php. |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Nov 17, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. |
1Phpgurukul 1Complaint Management System Jun 17, 2026 Nov 17, 2025 N/A· v4 4.6 MEDIUM· v3 N/A· v2 PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php. |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php. |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page. |
1Phpgurukul 1Online Shopping Portal Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php. |
1Phpgurukul 1Complaint Management System Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php. |
1Phpgurukul 1Complaint Management System Jun 17, 2026 Nov 17, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-search.php. |
1Phpgurukul 1Complaint Management System Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php. |
1Phpgurukul 1Complaint Management System Jun 17, 2026 Nov 17, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php. |
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php. |
PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php. |
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php. |
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php. |
1Phpgurukul 1Tourism Management System Jun 17, 2026 Nov 16, 2025 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A security flaw has been discovered in PHPGurukul Tourism Management System 1.0. The affected element is an unknown function of the file /admin/user-bookings.php. The manipulation of the argument uid results in sql injec...Show more |
PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php. |
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php. |
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php. |