Skip to content
Threat Feed

Vendor

PHPGurukul

6 briefs RSS
high advisory

SQL Injection in PHPGurukul Daily Expense Tracker System

An unauthenticated SQL injection vulnerability in the login component of PHPGurukul Daily Expense Tracker System 1.1 allows remote attackers to execute arbitrary database queries.

Daily Expense Tracker System web-vulnerability sql-injection cve-2026-90844
2r 1t 1c
high advisory

Authentication Bypass in PHPGurukul Blood Donor Management System

PHPGurukul Blood Donor Management System 1.0 is vulnerable to an authentication bypass in the admin dashboard, allowing remote attackers to gain unauthorized administrative access.

Blood Donor Management System web-application authentication-bypass vulnerability
2t 1c
low advisory

Stored XSS Vulnerability in Phpgurukul Online Birth Certificate System

Phpgurukul Online Birth Certificate System version 1.0 is vulnerable to Stored Cross-Site Scripting (XSS) via the profile name field, allowing authenticated attackers to execute arbitrary JavaScript in the context of other users.

Online Birth Certificate System
1r 2t 1c
low advisory

Stored XSS Vulnerability in Phpgurukul Teachers Record Management System

A stored cross-site scripting (XSS) vulnerability in Phpgurukul Teachers Record Management System version 1.0 allows authenticated administrators to execute arbitrary JavaScript in the context of other users.

Teachers Record Management System xss web-vulnerability stored-xss
1r 2t 1c
high threat

SQL Injection in PHPGurukul Complaint Management System

PHPGurukul Complaint Management System 1.0 contains an unauthenticated SQL injection vulnerability in the user/check_availability.php file, allowing remote attackers to execute arbitrary database commands.

exploited Complaint Management System sql-injection web-vulnerability
1r 1t 1c
high threat

PHPGurukul Online Course Registration 3.1 SQL Injection Vulnerability

A SQL injection vulnerability (CVE-2026-5814) exists in PHPGurukul Online Course Registration 3.1, allowing remote attackers to execute arbitrary SQL queries by manipulating the 'regno' argument in the /admin/check_availability.php file.

exploited Online Course Registration sql-injection web-application vulnerability
2r 1t 1c