PHPGurukul Student Record System

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in PHPGurukul Student Record System.

By the Year

In 2026 there have been 0 vulnerabilities in PHPGurukul Student Record System. Last year, in 2025 Student Record System had 19 security vulnerabilities published. Right now, Student Record System is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 19 8.22
2024 3 9.30
2023 0 0.00
2022 0 0.00
2021 3 9.13

It may take a day or so for new Student Record System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent PHPGurukul Student Record System Security Vulnerabilities

CSRF in PHPGurukul SRS v3.2 manage-students.php Enables Auth Admin Deletion
CVE-2025-63955 7.5 - High - November 18, 2025

A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS).

Session Riding

SQL Injection via register.php in PHPGurukul Student Record System 3.20
CVE-2024-44630 6.5 - Medium - November 14, 2025

Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2, course-short, income, category, ph, country, state, city, padd, cadd, and gender.

SQL Injection

PHPGurukul SR System 3.20 SQLi via id/emailid in password-recovery.php
CVE-2024-44632 6.5 - Medium - November 14, 2025

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.

SQL Injection

PHPGurukul Student Record System 3.20: SQL Injection via currentpassword
CVE-2024-44633 6.5 - Medium - November 14, 2025

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php.

SQL Injection

XSS via adminname/aemailid in PHPGurukul SR System 3.20
CVE-2024-44635 6.1 - Medium - November 14, 2025

PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php.

XSS

SQL Injection in PHPGurukul Student Record System 3.20 via /admin-profile.php
CVE-2024-44636 6.5 - Medium - November 14, 2025

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php.

SQL Injection

SQLi in PHPGurukul SRS 3.20 via add-course.php
CVE-2024-44640 6.5 - Medium - November 14, 2025

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php.

SQL Injection

PHPGurukul 3.2 SQLi via session param in register.php
CVE-2025-6915 8.8 - High - June 30, 2025

A vulnerability, which was classified as critical, has been found in PHPGurukul Student Record System 3.2. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument session leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

CVE-2025-6914: PHPGurukul SR System 3.2 SQLi via fmarks2
CVE-2025-6914 8.8 - High - June 30, 2025

A vulnerability classified as critical was found in PHPGurukul Student Record System 3.2. Affected by this vulnerability is an unknown functionality of the file /edit-student.php. The manipulation of the argument fmarks2 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQL injection in PHPGurukul Student Record System 3.2 /admin-profile.php
CVE-2025-6913 8.8 - High - June 30, 2025

A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown function of the file /admin-profile.php. The manipulation of the argument aemailid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLI in PHPGurukul Student Record System 3.2 via /manage-students.php del param
CVE-2025-6912 8.8 - High - June 30, 2025

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been rated as critical. This issue affects some unknown processing of the file /manage-students.php. The manipulation of the argument del leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi in PHPGurukul Student Record System 3.2 – /manage-subjects.php (del param)
CVE-2025-6911 8.8 - High - June 30, 2025

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /manage-subjects.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi in PHPGurukul Student Record System 3.2 session.php
CVE-2025-6910 8.8 - High - June 30, 2025

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been classified as critical. This affects an unknown part of the file /session.php. The manipulation of the argument session leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Student Record System 3.20 SQLi via $cshortname (PHP/MySQL)
CVE-2024-27685 - June 25, 2025

SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables.

PHPGurukul Student Record System 3.20 Remote SQLi via login.php
CVE-2025-5216 9.8 - Critical - May 27, 2025

A vulnerability classified as critical was found in PHPGurukul Student Record System 3.20. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

CVE-2025-4112: PHPGurukul SRS 3.20 SQLi /add-course.php
CVE-2025-4112 9.8 - Critical - April 30, 2025

A vulnerability was found in PHPGurukul Student Record System 3.20. It has been declared as critical. This vulnerability affects unknown code of the file /add-course.php. The manipulation of the argument course-short leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Critical SQLi via sub1 in PHPGurukul Student Record System 3.20 /add-subject.php
CVE-2025-4108 9.8 - Critical - April 30, 2025

A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /add-subject.php. The manipulation of the argument sub1 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi in PHPGurukul Student Record System 3.20 change-password.php
CVE-2025-4073 9.8 - Critical - April 29, 2025

A vulnerability was found in PHPGurukul Student Record System 3.20. It has been classified as critical. Affected is an unknown function of the file /change-password.php. The manipulation of the argument currentpassword leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Critical SQLi in PHPGurukul Student Record System 3.2 /password-recovery.php
CVE-2025-1902 9.8 - Critical - March 04, 2025

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

PHPGurukul 3.20 /edit-subject.php SQLi Remote Critical
CVE-2024-3771 8.8 - High - April 15, 2024

A vulnerability was found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this issue is some unknown functionality of the file /edit-subject.php. The manipulation of the argument sub1/sub2/sub3/sub4/udate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-260618 is the identifier assigned to this vulnerability.

SQL Injection

PHPGurukul Student Record System 3.20 SQLi in /manage-courses.php via del param
CVE-2024-3770 - April 15, 2024

A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage-courses.php?del=1. The manipulation of the argument del leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260617 was assigned to this vulnerability.

SQL Injection

PHPGurukul Student Record System 3.20 /login.php SQLi
CVE-2024-3769 9.8 - Critical - April 15, 2024

A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /login.php. The manipulation of the argument id/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-260616.

SQL Injection

SQL injection vulnerability in PHPGurukul Student Record System 4.0
CVE-2021-26765 9.8 - Critical - July 22, 2021

SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.

SQL Injection

SQL injection vulnerability in PHPGurukul Student Record System 4.0
CVE-2021-26762 8.8 - High - July 22, 2021

SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.

SQL Injection

SQL injection vulnerability in PHPGurukul Student Record System v 4.0
CVE-2021-26764 8.8 - High - July 22, 2021

SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit-std.php.

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for PHPGurukul Student Record System or by PHPGurukul? Click the Watch button to subscribe.

 

PHPGurukul
Vendor

subscribe