PHPGurukul
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any PHPGurukul product.
RSS Feeds for PHPGurukul security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in PHPGurukul products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by PHPGurukul Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 20 vulnerabilities in PHPGurukul with an average score of 6.0 out of ten. Last year, in 2025 PHPGurukul had 586 security vulnerabilities published. Right now, PHPGurukul is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 2.64
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 20 | 5.97 |
| 2025 | 586 | 8.60 |
| 2024 | 216 | 7.46 |
| 2023 | 107 | 7.03 |
| 2022 | 42 | 7.74 |
| 2021 | 43 | 7.40 |
| 2020 | 21 | 7.81 |
It may take a day or so for new PHPGurukul vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent PHPGurukul Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-3403 | Mar 02, 2026 |
CVE-2026-3403: XSS in PHPGurukul SRMS 1.0 via /edit-subject.phpA vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used. |
|
| CVE-2026-3402 | Mar 02, 2026 |
XSS in PHPGurukul Student Record Management System v1.0 (edit-course.php)A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2025-70062 | Feb 18, 2026 |
CSRF in PHPGurukul HMS 4.0 Add Doctor modulePHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. This allows remote attackers to create arbitrary Doctor accounts (privileged users) by tricking an authenticated administrator into visiting a malicious page. |
Hospital Management System
|
| CVE-2026-2179 | Feb 08, 2026 |
SQLi via ID param in PHPGurukul HM 4.0 manage-users.phpA vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. |
Hospital Management System
|
| CVE-2026-2134 | Feb 08, 2026 |
SQLi via ID in PHPGurukul HMS 4.0 manage-doctors.phpA security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unknown function of the file /hms/admin/manage-doctors.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. |
Hospital Management System
|
| CVE-2026-2088 | Feb 07, 2026 |
SQLi in PHPGurukul Beauty Parlour 1.1 /admin/accepted-appointment.phpA vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
Beauty Parlour Management System
|
| CVE-2026-1550 | Jan 28, 2026 |
PHPGurukul HMS 1.0 Admin Dashboard Improper Auth Remote ExploitA security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. |
Hospital Management System
|
| CVE-2026-1424 | Jan 26, 2026 |
PHPGurukul News Portal 1.0 - Unrestricted File Upload via Profile Pic HandlerA vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. |
News Portal
|
| CVE-2026-1160 | Jan 19, 2026 |
SQLi via Searchdata in PHPGurukul DirMS 1.0 index.phpA security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of the component Search. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. |
Directory Management System
|
| CVE-2026-1142 | Jan 19, 2026 |
XSRF via unknown function in PHPGurukul News Portal 1.0A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. |
News Portal
|
| CVE-2026-1141 | Jan 19, 2026 |
PHPGurukul 1.0 Add Sub-Admin Page Improper Auth (Remote)A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component Add Sub-Admin Page. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit is publicly available and might be used. |
News Portal
|
| CVE-2025-70891 | Jan 15, 2026 |
XSS in Phpgurukul Cyber Cafe Mgmt Sys v1.0 User ManagementA stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user management module. The application does not properly sanitize or encode user-supplied input submitted via the uadd parameter in the add-users.php endpoint. An authenticated attacker can inject arbitrary JavaScript code that is persistently stored in the database. The malicious payload is triggered when a privileged user clicks the View button on the view-allusers.php page. |
Cyber Cafe Management System
|
| CVE-2025-69990 | Jan 13, 2026 |
phpgurukul News Portal V4.1 Arbitrary File Deletion via remove_file.phpphpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted. |
News Portal
|
| CVE-2025-69991 | Jan 13, 2026 |
SQLi in phpgurukul News Portal v4.1 check_availablity.phpphpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php. |
News Portal Project
|
| CVE-2025-69992 | Jan 13, 2026 |
File Upload Vulnerability in phpgurukul News Portal 4.1 via upload.phpphpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication. |
News Portal Project
|
| CVE-2026-0803 | Jan 09, 2026 |
SQLi in PHPGurukul ORRS enroll.php <=3.1A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the file /enroll.php. The manipulation of the argument studentregno/Pincode/session/department/level/course/sem results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. |
Online Course Registration System
|
| CVE-2026-0733 | Jan 08, 2026 |
SQLi in PHPGurukul Online Course Reg System <=3.1 via /admin/manage-students.phpA vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown function of the file /onlinecourse/admin/manage-students.php. This manipulation of the argument id/cid causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. |
Online Course Registration System
|
| CVE-2026-0730 | Jan 08, 2026 |
CVE-2026-0730 PHPGurukul SLMS 1.0 XSS via SVG File HandlerA flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/slms/adminviews.py of the component SVG File Handler. Executing a manipulation of the argument profile_pic can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used. |
Staff Leave Management System
|
| CVE-2026-0547 | Jan 02, 2026 |
PHPGurukul 3.1: Unrestricted File Upload via /admin/edit-student-profile.phpA vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-student-profile.php of the component Student Registration Page. The manipulation of the argument photo results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used. |
Online Course Registration
|
| CVE-2025-15406 | Jan 01, 2026 |
Missing Authorization in PHPGurukul OR v3.1 and earlierA flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. |
Online Course Registration
|
| CVE-2025-15390 | Dec 31, 2025 |
A security flaw has been discovered in PHPGurukul Small CRM 4.0A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. |
Small Crm
|
| CVE-2025-65647 | Nov 25, 2025 |
CVE-2025-65647: IDOR in Track Order (PHPGURUKUL OS Portal 2.1)Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter. |
Online Shopping Portal
|
| CVE-2025-13577 | Nov 24, 2025 |
XSS in PHPGurukul 2.1 register-complaint.php via cdetailsA flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing a manipulation of the argument cdetails can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. |
Hostel Management System
|
| CVE-2025-63955 | Nov 18, 2025 |
CSRF in PHPGurukul SRS v3.2 manage-students.php Enables Auth Admin DeletionA Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS). |
Student Record System
|
| CVE-2024-44664 | Nov 17, 2025 |
PHPGurukul 2.0: SQLi via product-details.phpPHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php. |
Online Shopping Portal
|
| CVE-2024-44654 | Nov 17, 2025 |
CVE-2024-44654: SQL Injection in PHPGurukul CMS 2.0 reset-password.phpPHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php. |
Complaint Management System
|
| CVE-2024-44655 | Nov 17, 2025 |
XSS in PHPGurukul CMS 2.0 via search param in user-search.phpPHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-search.php. |
Complaint Management System
|
| CVE-2024-44658 | Nov 17, 2025 |
PHPGurukul Complaint Management System 2.0 SQLi via subcategory.phpPHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php. |
Complaint Management System
|
| CVE-2024-44660 | Nov 17, 2025 |
PHPGurukul Online Shopping Portal 2.0 SQL Injection via login.phpPHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php. |
Online Shopping Portal
|
| CVE-2024-44663 | Nov 17, 2025 |
SQL Injection in PHPGurukul Online Shopping Portal 2.0 - search-result.phpPHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php. |
Online Shopping Portal
|
| CVE-2024-46335 | Nov 17, 2025 |
PHPGurukul CMS 2.0 XSS via fromdate/todate in between-date-userreport.phpPHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php. |
Complaint Management System
|
| CVE-2024-44657 | Nov 17, 2025 |
SQLI via fromdate & todate in PHPGurukul CMS 2.0PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php. |
Complaint Management System
|
| CVE-2024-44641 | Nov 17, 2025 |
SQLi in PHPGurukul Small CRM 3.0 via oldpass in change-password.phpPHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php. |
Small Crm
|
| CVE-2024-44644 | Nov 17, 2025 |
SQLi in PHPGurukul Small CRM 3.0 via manage-tickets.phpPHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php. |
Small Crm
|
| CVE-2024-44648 | Nov 17, 2025 |
PHPGurukul Small CRM 3.0 SQLi via id/adminremark in quote-details.phpPHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php. |
Small Crm
|
| CVE-2025-13247 | Nov 16, 2025 |
SQLi via uid in /admin/user-bookings.php of PHPGurukul Tourism Mgmt 1.0A security flaw has been discovered in PHPGurukul Tourism Management System 1.0. The affected element is an unknown function of the file /admin/user-bookings.php. The manipulation of the argument uid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. |
Tourism Management System
|
| CVE-2024-44630 | Nov 14, 2025 |
SQL Injection via register.php in PHPGurukul Student Record System 3.20Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2, course-short, income, category, ph, country, state, city, padd, cadd, and gender. |
Student Record System
|
| CVE-2024-44632 | Nov 14, 2025 |
PHPGurukul SR System 3.20 SQLi via id/emailid in password-recovery.phpPHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php. |
Student Record System
|
| CVE-2024-44633 | Nov 14, 2025 |
PHPGurukul Student Record System 3.20: SQL Injection via currentpasswordPHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php. |
Student Record System
|
| CVE-2024-44635 | Nov 14, 2025 |
XSS via adminname/aemailid in PHPGurukul SR System 3.20PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php. |
Student Record System
|
| CVE-2024-44636 | Nov 14, 2025 |
SQL Injection in PHPGurukul Student Record System 3.20 via /admin-profile.phpPHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php. |
Student Record System
|
| CVE-2024-44640 | Nov 14, 2025 |
SQLi in PHPGurukul SRS 3.20 via add-course.phpPHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php. |
Student Record System
|
| CVE-2025-12616 | Nov 03, 2025 |
PHPGurukul News Portal 1.0 Debug Code Injection CVE-2025-12616A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertion of sensitive information into debugging code. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used. |
News Portal
|
| CVE-2025-12615 | Nov 03, 2025 |
PHPGurukul News Portal 1.0 Hard-Coded SECRET_KEY via settings.pyA security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been disclosed publicly and may be used. |
News Portal
|
| CVE-2025-50363 | Nov 03, 2025 |
XSS in Phpgurukul Maid Hiring 1.0 name field (maid-hiring.php)Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field. |
Maid Hiring Management System
|
| CVE-2025-12312 | Oct 27, 2025 |
PHPGurukul Curfew e-Pass MS 1.0 XSS via view-pass-detail.php Fullname/CategoryA flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file view-pass-detail.php. This manipulation of the argument Fullname/Category causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. |
Curfew E Pass Management System
|
| CVE-2025-12311 | Oct 27, 2025 |
CrossSite Scripting in PHPGurukul Curfew ePass 1.0 edit-category-detail.phpA vulnerability was detected in PHPGurukul Curfew e-Pass Management System 1.0. This issue affects some unknown processing of the file edit-category-detail.php. The manipulation of the argument catname results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. |
Curfew E Pass Management System
|
| CVE-2025-12303 | Oct 27, 2025 |
XSS via admin-profile.php in PHPGurukul Curfew e-Pass MS 1.0A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of the file admin-profile.php. Executing a manipulation of the argument adminname/email can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. |
Curfew E Pass Management System
|
| CVE-2025-61255 | Oct 21, 2025 |
Bank Locker Management System: XSS via /search paramBank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search parameter, where unsanitized input allows arbitrary HTML and JavaScript injection, potentially resulting in information disclosure and user redirection. |
Bank Locker Management System
|
| CVE-2025-11507 | Oct 08, 2025 |
SQLi in PHPGurukul BM System 1.1 via /admin/search-invoices.phpA weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/search-invoices.php. This manipulation of the argument searchdata causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
Beauty Parlour Management System
|