PHPGurukul Student Record System
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in PHPGurukul Student Record System.
By the Year
In 2026 there have been 0 vulnerabilities in PHPGurukul Student Record System. Last year, in 2025 Student Record System had 19 security vulnerabilities published. Right now, Student Record System is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 19 | 8.22 |
| 2024 | 3 | 9.30 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 3 | 9.13 |
It may take a day or so for new Student Record System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent PHPGurukul Student Record System Security Vulnerabilities
CSRF in PHPGurukul SRS v3.2 manage-students.php Enables Auth Admin Deletion
CVE-2025-63955
7.5 - High
- November 18, 2025
A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS).
Session Riding
SQL Injection via register.php in PHPGurukul Student Record System 3.20
CVE-2024-44630
6.5 - Medium
- November 14, 2025
Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2, course-short, income, category, ph, country, state, city, padd, cadd, and gender.
SQL Injection
PHPGurukul SR System 3.20 SQLi via id/emailid in password-recovery.php
CVE-2024-44632
6.5 - Medium
- November 14, 2025
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.
SQL Injection
PHPGurukul Student Record System 3.20: SQL Injection via currentpassword
CVE-2024-44633
6.5 - Medium
- November 14, 2025
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php.
SQL Injection
XSS via adminname/aemailid in PHPGurukul SR System 3.20
CVE-2024-44635
6.1 - Medium
- November 14, 2025
PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php.
XSS
SQL Injection in PHPGurukul Student Record System 3.20 via /admin-profile.php
CVE-2024-44636
6.5 - Medium
- November 14, 2025
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php.
SQL Injection
SQLi in PHPGurukul SRS 3.20 via add-course.php
CVE-2024-44640
6.5 - Medium
- November 14, 2025
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php.
SQL Injection
PHPGurukul 3.2 SQLi via session param in register.php
CVE-2025-6915
8.8 - High
- June 30, 2025
A vulnerability, which was classified as critical, has been found in PHPGurukul Student Record System 3.2. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument session leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
CVE-2025-6914: PHPGurukul SR System 3.2 SQLi via fmarks2
CVE-2025-6914
8.8 - High
- June 30, 2025
A vulnerability classified as critical was found in PHPGurukul Student Record System 3.2. Affected by this vulnerability is an unknown functionality of the file /edit-student.php. The manipulation of the argument fmarks2 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
SQL injection in PHPGurukul Student Record System 3.2 /admin-profile.php
CVE-2025-6913
8.8 - High
- June 30, 2025
A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown function of the file /admin-profile.php. The manipulation of the argument aemailid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
SQLI in PHPGurukul Student Record System 3.2 via /manage-students.php del param
CVE-2025-6912
8.8 - High
- June 30, 2025
A vulnerability was found in PHPGurukul Student Record System 3.2. It has been rated as critical. This issue affects some unknown processing of the file /manage-students.php. The manipulation of the argument del leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
SQLi in PHPGurukul Student Record System 3.2 – /manage-subjects.php (del param)
CVE-2025-6911
8.8 - High
- June 30, 2025
A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /manage-subjects.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
SQLi in PHPGurukul Student Record System 3.2 session.php
CVE-2025-6910
8.8 - High
- June 30, 2025
A vulnerability was found in PHPGurukul Student Record System 3.2. It has been classified as critical. This affects an unknown part of the file /session.php. The manipulation of the argument session leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Student Record System 3.20 SQLi via $cshortname (PHP/MySQL)
CVE-2024-27685
- June 25, 2025
SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables.
PHPGurukul Student Record System 3.20 Remote SQLi via login.php
CVE-2025-5216
9.8 - Critical
- May 27, 2025
A vulnerability classified as critical was found in PHPGurukul Student Record System 3.20. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
CVE-2025-4112: PHPGurukul SRS 3.20 SQLi /add-course.php
CVE-2025-4112
9.8 - Critical
- April 30, 2025
A vulnerability was found in PHPGurukul Student Record System 3.20. It has been declared as critical. This vulnerability affects unknown code of the file /add-course.php. The manipulation of the argument course-short leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Critical SQLi via sub1 in PHPGurukul Student Record System 3.20 /add-subject.php
CVE-2025-4108
9.8 - Critical
- April 30, 2025
A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /add-subject.php. The manipulation of the argument sub1 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
SQLi in PHPGurukul Student Record System 3.20 change-password.php
CVE-2025-4073
9.8 - Critical
- April 29, 2025
A vulnerability was found in PHPGurukul Student Record System 3.20. It has been classified as critical. Affected is an unknown function of the file /change-password.php. The manipulation of the argument currentpassword leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
Critical SQLi in PHPGurukul Student Record System 3.2 /password-recovery.php
CVE-2025-1902
9.8 - Critical
- March 04, 2025
A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
SQL Injection
PHPGurukul 3.20 /edit-subject.php SQLi Remote Critical
CVE-2024-3771
8.8 - High
- April 15, 2024
A vulnerability was found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this issue is some unknown functionality of the file /edit-subject.php. The manipulation of the argument sub1/sub2/sub3/sub4/udate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-260618 is the identifier assigned to this vulnerability.
SQL Injection
PHPGurukul Student Record System 3.20 SQLi in /manage-courses.php via del param
CVE-2024-3770
- April 15, 2024
A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage-courses.php?del=1. The manipulation of the argument del leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260617 was assigned to this vulnerability.
SQL Injection
PHPGurukul Student Record System 3.20 /login.php SQLi
CVE-2024-3769
9.8 - Critical
- April 15, 2024
A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /login.php. The manipulation of the argument id/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260616.
SQL Injection
SQL injection vulnerability in PHPGurukul Student Record System 4.0
CVE-2021-26765
9.8 - Critical
- July 22, 2021
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.
SQL Injection
SQL injection vulnerability in PHPGurukul Student Record System 4.0
CVE-2021-26762
8.8 - High
- July 22, 2021
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.
SQL Injection
SQL injection vulnerability in PHPGurukul Student Record System v 4.0
CVE-2021-26764
8.8 - High
- July 22, 2021
SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit-std.php.
SQL Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for PHPGurukul Student Record System or by PHPGurukul? Click the Watch button to subscribe.