Phpgurukul
Phpgurukul Daily Expense Tracker System: vulnerabilidades y CVE
Phpgurukul Daily Expense Tracker System tiene 15 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses3
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-90846 | Media (5.5) | 0.43% | — | 15 sept 2026 | A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql… |
| CVE-2026-90845 | Baja (2) | 0.35% | — | 15 sept 2026 | A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to… |
| CVE-2026-90844 | Media (5.5) | 0.43% | — | 15 sept 2026 | A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email… |
| CVE-2025-5546 | Media (5.3) | 0.40% | — | 4 jun 2025 | A vulnerability classified as critical was found in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /expense-reports-detailed.php. The manipulation of the argument… |
| CVE-2025-5368 | Media (5.3) | 0.42% | — | 31 may 2025 | A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. This issue affects some unknown processing of the file /expense-yearwise-reports-detailed.php. The manipulation of… |
| CVE-2025-4925 | Media (6.9) | 0.51% | — | 19 may 2025 | A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /expense-monthwise-reports-detailed.php.… |
| CVE-2025-4908 | Media (6.9) | 0.58% | — | 19 may 2025 | A vulnerability classified as critical has been found in PHPGurukul Daily Expense Tracker System 1.1. This affects an unknown part of the file /expense-datewise-reports-detailed.php. The manipulation of the argument… |
| CVE-2025-4907 | Media (6.9) | 0.58% | — | 19 may 2025 | A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /forgot-password.php. The manipulation of the… |
| CVE-2025-4785 | Media (6.9) | 0.73% | — | 16 may 2025 | A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user-profile.php. The manipulation of the… |
| CVE-2025-25351 | Crítica (9.8) | 0.50% | — | 12 feb 2025 | PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter. |
| CVE-2025-25349 | Crítica (9.8) | 0.50% | — | 12 feb 2025 | PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem parameter. |
| CVE-2021-26304 | Media (5.4) | 0.58% | — | 29 ene 2021 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter. |
| CVE-2021-26303 | Media (6.1) | 0.78% | — | 29 ene 2021 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field. |
| CVE-2020-10107 | Media (5.4) | 0.53% | — | 5 mar 2020 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS, as demonstrated by the ExpenseItem or ExpenseCost parameter in manage-expense.php. |
| CVE-2020-10106 | Crítica (9.8) | 1.2% | — | 5 mar 2020 | PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to SQL injection, as demonstrated by the email parameter in index.php or register.php. The SQL injection allows to dump the MySQL database and to bypass the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Phpgurukul
Hospital Management System · 62Online Shopping Portal · 43ZOO Management System · 37ART Gallery Management System · 36Online Fire Reporting System · 32Complaint Management System · 32Student Record System · 29Beauty Parlour Management System · 28User Registration & Login AND User Management System · 25Land Record System · 25Pre-school Enrollment System · 25Dairy Farm Shop Management System · 24