Vulnerabilities (CVE)

Filtered by vendor Phpgurukul Subscribe
Total 974 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-35156 1 Phpgurukul 1 Bus Pass Management System 2026-07-09 N/A 9.8 CRITICAL
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
CVE-2022-35155 1 Phpgurukul 1 Bus Pass Management System 2026-07-09 N/A 6.1 MEDIUM
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.
CVE-2020-22168 1 Phpgurukul 1 Hospital Management System In Php 2026-07-09 5.0 MEDIUM 7.5 HIGH
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
CVE-2025-57145 1 Phpgurukul 1 Auto Taxi Stand Management System 2026-07-05 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and executed when a user or administrator accesses the affected report page. This allows attackers to exfiltrate session cookies, hijack user sessions, and perform unauthorized actions in the context of the victims browser.
CVE-2025-50494 1 Phpgurukul 1 Car Washing Management System 2026-07-05 N/A 7.5 HIGH
Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.
CVE-2025-50493 1 Phpgurukul 1 Doctor Appointment Management System 2026-07-05 N/A 7.5 HIGH
Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to execute a session hijacking attack.
CVE-2025-50492 1 Phpgurukul 1 E-diary Management System 2026-07-05 N/A 7.5 HIGH
Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a session hijacking attack.
CVE-2025-50491 1 Phpgurukul 1 Bank Locker Management System 2026-07-05 N/A 7.1 HIGH
Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.
CVE-2025-50490 1 Phpgurukul 1 Student Result Management System 2026-07-05 N/A 7.5 HIGH
Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.
CVE-2025-50489 1 Phpgurukul 1 Student Result Management System 2026-07-05 N/A 7.5 HIGH
Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.
CVE-2025-50488 1 Phpgurukul 1 Online Library Management System 2026-07-05 N/A 7.1 HIGH
Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack.
CVE-2025-50487 1 Phpgurukul 1 Blood Bank \& Donor Management System 2026-07-05 N/A 7.1 HIGH
Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hijacking attack.
CVE-2025-50486 1 Phpgurukul 1 E-diary Management System 2026-07-05 N/A 7.1 HIGH
Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack.
CVE-2025-50485 1 Phpgurukul 1 Online Course Registration 2026-07-05 N/A 7.1 HIGH
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack.
CVE-2025-50484 1 Phpgurukul 1 Small Crm 2026-07-05 N/A 7.1 HIGH
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.
CVE-2025-57119 1 Phpgurukul 1 Online Library Management System 2026-07-05 N/A 9.8 CRITICAL
An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function
CVE-2025-45953 1 Phpgurukul 1 Hostel Management System 2026-07-05 N/A 9.1 CRITICAL
A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely
CVE-2025-45949 1 Phpgurukul 1 User Registration \& Login And User Management System 2026-07-05 N/A 9.8 CRITICAL
A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account takeover.
CVE-2025-45947 1 Phpgurukul 1 Online Banquet Booking System 2026-07-05 N/A 9.8 CRITICAL
An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component
CVE-2024-53481 1 Phpgurukul 1 Beauty Parlour Management System 2026-07-05 N/A 6.1 MEDIUM
A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.