PHPGurukul

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any PHPGurukul product.

RSS Feeds for PHPGurukul security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in PHPGurukul products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by PHPGurukul Sorted by Most Security Vulnerabilities since 2018

 
 
 
 
 
 
 
 
 

PHPGurukul Land Record System25 vulnerabilities

 
 
 
 
 

PHPGurukul Boat Booking System18 vulnerabilities

 
 
 
 
 

PHPGurukul Small Crm17 vulnerabilities

 
 
 
 
 
 
 

PHPGurukul News Portal13 vulnerabilities

 
 
 

PHPGurukul Job Portal12 vulnerabilities

 
 

PHPGurukul News Portal Project10 vulnerabilities

 
 
 
 
 
 
 
 
 
 

PHPGurukul Car Rental Portal5 vulnerabilities

 

PHPGurukul Ifsc Code Finder4 vulnerabilities

 
 
 
 
 
 
 
 
 

By the Year

In 2026 there have been 20 vulnerabilities in PHPGurukul with an average score of 6.0 out of ten. Last year, in 2025 PHPGurukul had 586 security vulnerabilities published. Right now, PHPGurukul is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 2.64




Year Vulnerabilities Average Score
2026 20 5.97
2025 586 8.60
2024 216 7.46
2023 107 7.03
2022 42 7.74
2021 43 7.40
2020 21 7.81

It may take a day or so for new PHPGurukul vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent PHPGurukul Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-3403 Mar 02, 2026
CVE-2026-3403: XSS in PHPGurukul SRMS 1.0 via /edit-subject.php A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVE-2026-3402 Mar 02, 2026
XSS in PHPGurukul Student Record Management System v1.0 (edit-course.php) A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
CVE-2025-70062 Feb 18, 2026
CSRF in PHPGurukul HMS 4.0 Add Doctor module PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. This allows remote attackers to create arbitrary Doctor accounts (privileged users) by tricking an authenticated administrator into visiting a malicious page.
Hospital Management System
CVE-2026-2179 Feb 08, 2026
SQLi via ID param in PHPGurukul HM 4.0 manage-users.php A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Hospital Management System
CVE-2026-2134 Feb 08, 2026
SQLi via ID in PHPGurukul HMS 4.0 manage-doctors.php A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unknown function of the file /hms/admin/manage-doctors.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Hospital Management System
CVE-2026-2088 Feb 07, 2026
SQLi in PHPGurukul Beauty Parlour 1.1 /admin/accepted-appointment.php A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Beauty Parlour Management System
CVE-2026-1550 Jan 28, 2026
PHPGurukul HMS 1.0 Admin Dashboard Improper Auth Remote Exploit A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Hospital Management System
CVE-2026-1424 Jan 26, 2026
PHPGurukul News Portal 1.0 - Unrestricted File Upload via Profile Pic Handler A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
News Portal
CVE-2026-1160 Jan 19, 2026
SQLi via Searchdata in PHPGurukul DirMS 1.0 index.php A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of the component Search. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Directory Management System
CVE-2026-1142 Jan 19, 2026
XSRF via unknown function in PHPGurukul News Portal 1.0 A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
News Portal
CVE-2026-1141 Jan 19, 2026
PHPGurukul 1.0 Add Sub-Admin Page Improper Auth (Remote) A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component Add Sub-Admin Page. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit is publicly available and might be used.
News Portal
CVE-2025-70891 Jan 15, 2026
XSS in Phpgurukul Cyber Cafe Mgmt Sys v1.0 User Management A stored cross-site scripting (XSS) vulnerability exists in Phpgurukul Cyber Cafe Management System v1.0 within the user management module. The application does not properly sanitize or encode user-supplied input submitted via the uadd parameter in the add-users.php endpoint. An authenticated attacker can inject arbitrary JavaScript code that is persistently stored in the database. The malicious payload is triggered when a privileged user clicks the View button on the view-allusers.php page.
Cyber Cafe Management System
CVE-2025-69990 Jan 13, 2026
phpgurukul News Portal V4.1 Arbitrary File Deletion via remove_file.php phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted.
News Portal
CVE-2025-69991 Jan 13, 2026
SQLi in phpgurukul News Portal v4.1 check_availablity.php phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.
News Portal Project
CVE-2025-69992 Jan 13, 2026
File Upload Vulnerability in phpgurukul News Portal 4.1 via upload.php phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.
News Portal Project
CVE-2026-0803 Jan 09, 2026
SQLi in PHPGurukul ORRS enroll.php <=3.1 A vulnerability was found in PHPGurukul Online Course Registration System up to 3.1. This affects an unknown part of the file /enroll.php. The manipulation of the argument studentregno/Pincode/session/department/level/course/sem results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Online Course Registration System
CVE-2026-0733 Jan 08, 2026
SQLi in PHPGurukul Online Course Reg System <=3.1 via /admin/manage-students.php A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown function of the file /onlinecourse/admin/manage-students.php. This manipulation of the argument id/cid causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Online Course Registration System
CVE-2026-0730 Jan 08, 2026
CVE-2026-0730 PHPGurukul SLMS 1.0 XSS via SVG File Handler A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/slms/adminviews.py of the component SVG File Handler. Executing a manipulation of the argument profile_pic can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
Staff Leave Management System
CVE-2026-0547 Jan 02, 2026
PHPGurukul 3.1: Unrestricted File Upload via /admin/edit-student-profile.php A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-student-profile.php of the component Student Registration Page. The manipulation of the argument photo results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used.
Online Course Registration
CVE-2025-15406 Jan 01, 2026
Missing Authorization in PHPGurukul OR v3.1 and earlier A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Online Course Registration
CVE-2025-15390 Dec 31, 2025
A security flaw has been discovered in PHPGurukul Small CRM 4.0 A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Small Crm
CVE-2025-65647 Nov 25, 2025
CVE-2025-65647: IDOR in Track Order (PHPGURUKUL OS Portal 2.1) Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.
Online Shopping Portal
CVE-2025-13577 Nov 24, 2025
XSS in PHPGurukul 2.1 register-complaint.php via cdetails A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing a manipulation of the argument cdetails can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
Hostel Management System
CVE-2025-63955 Nov 18, 2025
CSRF in PHPGurukul SRS v3.2 manage-students.php Enables Auth Admin Deletion A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS).
Student Record System
CVE-2024-44664 Nov 17, 2025
PHPGurukul 2.0: SQLi via product-details.php PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.
Online Shopping Portal
CVE-2024-44654 Nov 17, 2025
CVE-2024-44654: SQL Injection in PHPGurukul CMS 2.0 reset-password.php PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php.
Complaint Management System
CVE-2024-44655 Nov 17, 2025
XSS in PHPGurukul CMS 2.0 via search param in user-search.php PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-search.php.
Complaint Management System
CVE-2024-44658 Nov 17, 2025
PHPGurukul Complaint Management System 2.0 SQLi via subcategory.php PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php.
Complaint Management System
CVE-2024-44660 Nov 17, 2025
PHPGurukul Online Shopping Portal 2.0 SQL Injection via login.php PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.
Online Shopping Portal
CVE-2024-44663 Nov 17, 2025
SQL Injection in PHPGurukul Online Shopping Portal 2.0 - search-result.php PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
Online Shopping Portal
CVE-2024-46335 Nov 17, 2025
PHPGurukul CMS 2.0 XSS via fromdate/todate in between-date-userreport.php PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php.
Complaint Management System
CVE-2024-44657 Nov 17, 2025
SQLI via fromdate & todate in PHPGurukul CMS 2.0 PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php.
Complaint Management System
CVE-2024-44641 Nov 17, 2025
SQLi in PHPGurukul Small CRM 3.0 via oldpass in change-password.php PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.
Small Crm
CVE-2024-44644 Nov 17, 2025
SQLi in PHPGurukul Small CRM 3.0 via manage-tickets.php PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.
Small Crm
CVE-2024-44648 Nov 17, 2025
PHPGurukul Small CRM 3.0 SQLi via id/adminremark in quote-details.php PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.
Small Crm
CVE-2025-13247 Nov 16, 2025
SQLi via uid in /admin/user-bookings.php of PHPGurukul Tourism Mgmt 1.0 A security flaw has been discovered in PHPGurukul Tourism Management System 1.0. The affected element is an unknown function of the file /admin/user-bookings.php. The manipulation of the argument uid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Tourism Management System
CVE-2024-44630 Nov 14, 2025
SQL Injection via register.php in PHPGurukul Student Record System 3.20 Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2, course-short, income, category, ph, country, state, city, padd, cadd, and gender.
Student Record System
CVE-2024-44632 Nov 14, 2025
PHPGurukul SR System 3.20 SQLi via id/emailid in password-recovery.php PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.
Student Record System
CVE-2024-44633 Nov 14, 2025
PHPGurukul Student Record System 3.20: SQL Injection via currentpassword PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php.
Student Record System
CVE-2024-44635 Nov 14, 2025
XSS via adminname/aemailid in PHPGurukul SR System 3.20 PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php.
Student Record System
CVE-2024-44636 Nov 14, 2025
SQL Injection in PHPGurukul Student Record System 3.20 via /admin-profile.php PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php.
Student Record System
CVE-2024-44640 Nov 14, 2025
SQLi in PHPGurukul SRS 3.20 via add-course.php PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php.
Student Record System
CVE-2025-12616 Nov 03, 2025
PHPGurukul News Portal 1.0 Debug Code Injection CVE-2025-12616 A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertion of sensitive information into debugging code. It is possible to initiate the attack remotely. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit is now public and may be used.
News Portal
CVE-2025-12615 Nov 03, 2025
PHPGurukul News Portal 1.0 Hard-Coded SECRET_KEY via settings.py A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been disclosed publicly and may be used.
News Portal
CVE-2025-50363 Nov 03, 2025
XSS in Phpgurukul Maid Hiring 1.0 name field (maid-hiring.php) Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.
Maid Hiring Management System
CVE-2025-12312 Oct 27, 2025
PHPGurukul Curfew e-Pass MS 1.0 XSS via view-pass-detail.php Fullname/Category A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file view-pass-detail.php. This manipulation of the argument Fullname/Category causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.
Curfew E Pass Management System
CVE-2025-12311 Oct 27, 2025
CrossSite Scripting in PHPGurukul Curfew ePass 1.0 edit-category-detail.php A vulnerability was detected in PHPGurukul Curfew e-Pass Management System 1.0. This issue affects some unknown processing of the file edit-category-detail.php. The manipulation of the argument catname results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used.
Curfew E Pass Management System
CVE-2025-12303 Oct 27, 2025
XSS via admin-profile.php in PHPGurukul Curfew e-Pass MS 1.0 A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of the file admin-profile.php. Executing a manipulation of the argument adminname/email can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
Curfew E Pass Management System
CVE-2025-61255 Oct 21, 2025
Bank Locker Management System: XSS via /search param Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search parameter, where unsanitized input allows arbitrary HTML and JavaScript injection, potentially resulting in information disclosure and user redirection.
Bank Locker Management System
CVE-2025-11507 Oct 08, 2025
SQLi in PHPGurukul BM System 1.1 via /admin/search-invoices.php A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/search-invoices.php. This manipulation of the argument searchdata causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Beauty Parlour Management System
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.